-

CVE-2026-90196

ASoC: SOF: validate topology volume range before allocation

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: validate topology volume range before allocation

SOF treats the topology mixer min and max values as non-negative indices
into its volume table. It stores them in signed fields, allocates max + 1
entries through an int argument, and later indexes the table with the
stored range.

An inverted range is invalid, while a maximum at or above INT_MAX cannot
be represented safely after the increment or in the signed fields.
Validate the complete range before storing it or allocating the table.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 311ce4fe7637d96608b6e57bf9ebbd8aabcf429e
Version < 992e130b888699d18da901b593d7a0fb75041a03
Status affected
Version 311ce4fe7637d96608b6e57bf9ebbd8aabcf429e
Version < cd63a1eb677e9548ba2d512be5dac4cb474ae145
Status affected
Version 311ce4fe7637d96608b6e57bf9ebbd8aabcf429e
Version < 8e1d63f5e272061208455b5aa4cc0d5bcbe5c1a8
Status affected
Version 311ce4fe7637d96608b6e57bf9ebbd8aabcf429e
Version < d2f41287b51a3261d447ae38000f7a6f5860663a
Status affected
Version 311ce4fe7637d96608b6e57bf9ebbd8aabcf429e
Version < 72d0b77412aef2cec554cc84e176658f2a48dafa
Status affected
Version 311ce4fe7637d96608b6e57bf9ebbd8aabcf429e
Version < a698e4a60fa54268a38f4e66378851a196cb139b
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.2
Status affected
Version 0
Version < 5.2
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.109
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/992e130b888699d18da901b593d7a0fb75041a03
https://git.kernel.org/stable/c/cd63a1eb677e9548ba2d512be5dac4cb474ae145
https://git.kernel.org/stable/c/8e1d63f5e272061208455b5aa4cc0d5bcbe5c1a8
https://git.kernel.org/stable/c/d2f41287b51a3261d447ae38000f7a6f5860663a
https://git.kernel.org/stable/c/72d0b77412aef2cec554cc84e176658f2a48dafa
https://git.kernel.org/stable/c/a698e4a60fa54268a38f4e66378851a196cb139b