CVE-2026-72302
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
In sof_ipc3_control_update(), the expected_size calculation uses firmware-provided cdata->num_elems in arithmetic that could overflow on 32-bit platforms, wrapping to a small value. This would allow the cdata->rhdr.hdr.size comparison to pass with mismatched sizes, potentially leading to out-of-bounds access in snd_sof_update_control.
Use check_mul_overflow() and check_add_overflow() to detect and reject overflowed size calculations.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 10f461d79c2d1afb22344986cc1b4631169cf25e < 6856b3c23b0995eefad5a6142b4365ef70e1fe4a | affected |
| Linux | Linux | 10f461d79c2d1afb22344986cc1b4631169cf25e < 89a2309a9eec80d4c19e3aed62c4f923594d1911 | affected |
| Linux | Linux | 10f461d79c2d1afb22344986cc1b4631169cf25e < ffd79e77f2fbacd7a5d40ad1d4c7f3f089a8f2f3 | affected |
| Linux | Linux | 10f461d79c2d1afb22344986cc1b4631169cf25e < 711d912b18763af62a63aa8f2419a774eb63bba4 | affected |
| Linux | Linux | 10f461d79c2d1afb22344986cc1b4631169cf25e < 312c7d2ebe696da3f885eee77d52297664e57c53 | affected |
| Linux | Linux | 10f461d79c2d1afb22344986cc1b4631169cf25e < 8791977d7289f6e9d2b014f60a5455f053a7bc04 | affected |
| Linux | Linux | 5.18 | affected |
| Linux | Linux | 0 < 5.18 | unaffected |
| Linux | Linux | 6.1.178 <= 6.1.* | unaffected |
| Linux | Linux | 6.6.145 <= 6.6.* | unaffected |
| Linux | Linux | 6.12.97 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.40 <= 6.18.* | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/6856b3c23b0995eefad5a6142b4365ef70e1fe4a
- https://git.kernel.org/stable/c/89a2309a9eec80d4c19e3aed62c4f923594d1911
- https://git.kernel.org/stable/c/ffd79e77f2fbacd7a5d40ad1d4c7f3f089a8f2f3
- https://git.kernel.org/stable/c/711d912b18763af62a63aa8f2419a774eb63bba4
- https://git.kernel.org/stable/c/312c7d2ebe696da3f885eee77d52297664e57c53
- https://git.kernel.org/stable/c/8791977d7289f6e9d2b014f60a5455f053a7bc04
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.