-

CVE-2026-90068

ASoC: dapm: Fix off-by-one check on the second enum channel

In the Linux kernel, the following vulnerability has been resolved:

ASoC: dapm: Fix off-by-one check on the second enum channel

The snd_soc_dapm_put_enum_double() rejects item[0] once it reaches
e->items, but it lets item[1] be equal to it.  Both go on to
snd_soc_enum_item_to_val(), which indexes e->values with no bound of
its own, so an enum with a value table reads one element past the end.

The indexing arrived with the MUX consolidation, which relaxed the
item[1] check in the same hunk.  The value MUX handler it deleted used
>= there, and the snd_soc_put_enum_double() in soc-ops.c still does.

Only adav80x pairs a value table with two shifts, and its second
channel looks accidental, but the control does report two values.
Writing three into it reads off the end of adav80x_mux_values.  The
core catches that only under CONFIG_SND_CTL_INPUT_VALIDATION, which
defaults off.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3727b4968453dbab8fe18f979d67285eb6b66801
Version < 57ab955bde747327fb2042516ae1b7192c30e881
Status affected
Version 3727b4968453dbab8fe18f979d67285eb6b66801
Version < 806fa4e1f2bf73c54bc4b6360790ecc69d095ca5
Status affected
Version 3727b4968453dbab8fe18f979d67285eb6b66801
Version < 496081b4edc1f6e662418831c5b14cddd8d7920c
Status affected
Version 3727b4968453dbab8fe18f979d67285eb6b66801
Version < faf539af1a595a26e5a081a4e512caee2bc2f4c5
Status affected
Version 3727b4968453dbab8fe18f979d67285eb6b66801
Version < 32fc048391112559c34cb88d13594546939a4cd6
Status affected
Version 3727b4968453dbab8fe18f979d67285eb6b66801
Version < 10a36512c21f861a03fba461a7ead09023df9c1b
Status affected
Version 3727b4968453dbab8fe18f979d67285eb6b66801
Version < 55126ef66298e43c69f192acebae8c7cc0022cf6
Status affected
Version 3727b4968453dbab8fe18f979d67285eb6b66801
Version < 14511c9b54ceeeef487409d73947c89ee8563590
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.15
Status affected
Version 0
Version < 3.15
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/57ab955bde747327fb2042516ae1b7192c30e881
https://git.kernel.org/stable/c/806fa4e1f2bf73c54bc4b6360790ecc69d095ca5
https://git.kernel.org/stable/c/496081b4edc1f6e662418831c5b14cddd8d7920c
https://git.kernel.org/stable/c/faf539af1a595a26e5a081a4e512caee2bc2f4c5
https://git.kernel.org/stable/c/32fc048391112559c34cb88d13594546939a4cd6
https://git.kernel.org/stable/c/10a36512c21f861a03fba461a7ead09023df9c1b
https://git.kernel.org/stable/c/55126ef66298e43c69f192acebae8c7cc0022cf6
https://git.kernel.org/stable/c/14511c9b54ceeeef487409d73947c89ee8563590