7.8

CVE-2026-97910

ASoC: sprd: validate compress buffer sizes against fixed allocations

In the Linux kernel, the following vulnerability has been resolved:

ASoC: sprd: validate compress buffer sizes against fixed allocations

sprd_platform_compr_open() allocates the stage 0 IRAM buffer (32K data
area) and the stage 1 DDR buffer (2M data area) with fixed sizes, but
sprd_platform_compr_copy() derives all copy lengths from the user
controlled runtime->fragment_size and the write() count, never
comparing them against the physical buffer sizes. The compress core
only checks fragment_size * fragments for an u32 overflow in
snd_compress_check_input(), so a local user can configure a logical
buffer of up to ~4GB via SNDRV_COMPRESS_SET_PARAMS, far exceeding the
fixed allocations.

A fragment_size larger than the 32K IRAM data area makes the stage 0
copy_from_user() overflow past the IRAM allocation, and a buffer_size
larger than the 2M DDR buffer makes the wrapping copy at the end of
sprd_platform_compr_copy() write fully user controlled data past the
buffer. No SNDRV_PCM_TRIGGER_START is needed, a write() in SETUP
state reaches the copy callback directly.

Reject parameters that do not fit into the fixed buffers in
set_params(), and fix the advertised max fragment size: 128K never
fitted into the 32K IRAM buffer. The caps values may have been carried over
from the qdsp6 driver, which allocates its buffers according to the
advertised maxima, unlike this driver. With 32K as max fragment size
the advertised limits are self-consistent: 32K * 64 = 2M equals the
DDR buffer size.

Discovered by Atuin - Automated Vulnerability Discovery Engine.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version cce1396936ef2b347d622b4d49718818eb32029d
Version < 2fada8276117215407afd1f59de5d2fe22aff01f
Status affected
Version cce1396936ef2b347d622b4d49718818eb32029d
Version < ad796a1bc1875da2ebb616ea9bc1f2994273fd02
Status affected
Version cce1396936ef2b347d622b4d49718818eb32029d
Version < 2e27144ba4b98bb3eb14aaccd4b088e2e69844e3
Status affected
Version cce1396936ef2b347d622b4d49718818eb32029d
Version < 1467e3989c6edf79d3898c78aa47027f31ee5acb
Status affected
Version cce1396936ef2b347d622b4d49718818eb32029d
Version < 38a9bb5221bcdece5507299f739c6751d8fc16b2
Status affected
Version cce1396936ef2b347d622b4d49718818eb32029d
Version < ff63b0adc4f6a5b61c8393d204fac44c594c4d39
Status affected
Version cce1396936ef2b347d622b4d49718818eb32029d
Version < 8064b73997f137c00a7e2e38295a763f9423928b
Status affected
Version cce1396936ef2b347d622b4d49718818eb32029d
Version < 7a4ce92d150b9e7ecf1a710a34d8cdeb590d3751
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.2
Status affected
Version 0
Version < 5.2
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.111
Status unaffected
Version <= 6.18.*
Version 6.18.53
Status unaffected
Version <= 7.2.*
Version 7.2.7
Status unaffected
Version <= *
Version 7.3-rc3
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.04
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/38a9bb5221bcdece5507299f739c6751d8fc16b2
https://git.kernel.org/stable/c/ff63b0adc4f6a5b61c8393d204fac44c594c4d39
https://git.kernel.org/stable/c/8064b73997f137c00a7e2e38295a763f9423928b
https://git.kernel.org/stable/c/7a4ce92d150b9e7ecf1a710a34d8cdeb590d3751
https://git.kernel.org/stable/c/1467e3989c6edf79d3898c78aa47027f31ee5acb
https://git.kernel.org/stable/c/2e27144ba4b98bb3eb14aaccd4b088e2e69844e3
https://git.kernel.org/stable/c/2fada8276117215407afd1f59de5d2fe22aff01f
https://git.kernel.org/stable/c/ad796a1bc1875da2ebb616ea9bc1f2994273fd02