CVE-2026-72303
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc4-control: Validate notification payload size
Validate MODULE_NOTIFICATION payload length before reading bytes/channel data in control update handling.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 2a28b5240f2b328495c6565d277f438dbc583d61 < c29f5b4498894aebb2f87b1a29bb320e2f9348f9 | affected |
| Linux | Linux | 2a28b5240f2b328495c6565d277f438dbc583d61 < 5bdfeccb7fbf6e000fc783cd8412732e67c1ad0c | affected |
| Linux | Linux | 7.0 | affected |
| Linux | Linux | 0 < 7.0 | unaffected |
| Linux | Linux | 7.1.5 <= 7.1.* | unaffected |
| Linux | Linux | 7.2 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/c29f5b4498894aebb2f87b1a29bb320e2f9348f9
- https://git.kernel.org/stable/c/5bdfeccb7fbf6e000fc783cd8412732e67c1ad0c
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.