CVE-2026-72263

Summary

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: topology: fix memory leak in snd_sof_load_topology

When the topology filename contains "dummy" and tplg_cnt is 0, the function returns -EINVAL directly without freeing the tplg_files allocated by kcalloc() at line 2497. This leaks memory on every such topology load attempt.

Fix this by setting ret = -EINVAL and jumping to the out: label, which already handles the kfree(tplg_files) cleanup.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux99c159279c6dfa2c4867c7f76875f58263f8f43b < 6ed7787c43ecf4ae27a3e700cab53a1ed646c7f8affected
LinuxLinux99c159279c6dfa2c4867c7f76875f58263f8f43b < d46f9f23897261da53ffbeb89d48a13982ba7d28affected
LinuxLinux6.19affected
LinuxLinux0 < 6.19unaffected
LinuxLinux7.1.5 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References