CVE-2026-72261

Summary

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control

In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocation size. If local_cdata->data->size was previously set to an inconsistent value, the memcpy could write past the allocated buffer.

Add a bounds check to ensure num_elems fits within the available space in the ipc_control_data allocation before copying.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux10f461d79c2d1afb22344986cc1b4631169cf25e < 1dc25a3e06364f48c4ef06016852f8b82425151aaffected
LinuxLinux10f461d79c2d1afb22344986cc1b4631169cf25e < ee781058cd4d71e4449f41cbe6a3b8c59daa2c51affected
LinuxLinux10f461d79c2d1afb22344986cc1b4631169cf25e < ecf67f1302f2080b4d241b973364aacda70ad740affected
LinuxLinux10f461d79c2d1afb22344986cc1b4631169cf25e < d3abaedf6a58469610136d2dace1a85cddf7afcfaffected
LinuxLinux10f461d79c2d1afb22344986cc1b4631169cf25e < 2a591bf6fd41fd14bdae689aafac4a9ee702c23caffected
LinuxLinux10f461d79c2d1afb22344986cc1b4631169cf25e < 390aa4c9339bb0ec0bc8d554e830faf93ca9d49eaffected
LinuxLinux5.18affected
LinuxLinux0 < 5.18unaffected
LinuxLinux6.1.178 <= 6.1.*unaffected
LinuxLinux6.6.145 <= 6.6.*unaffected
LinuxLinux6.12.97 <= 6.12.*unaffected
LinuxLinux6.18.40 <= 6.18.*unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References