CVE-2026-80743

Summary

In the Linux kernel, the following vulnerability has been resolved:

ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers

The irq handlers take a struct device pointer and call dev_get_drvdata() to obtain the driver data. However, the driver data is only set at the end of probe, after devm_request_irq(), so an interrupt taken in between causes the handlers to pass a NULL pointer to readl() and crash.

Pass the private data directly as the devm_request_irq() argument instead of the device pointer, matching what the handlers expect.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux6f6c3c36f0917be24587eeba818ab4fdfcb5465a < 7d857aec162fb02d10ce326aecc1ac7509c31f43affected
LinuxLinux6f6c3c36f0917be24587eeba818ab4fdfcb5465a < a85315f2eb06adc5597a7103e1910fc7d0d35ffdaffected
LinuxLinux6f6c3c36f0917be24587eeba818ab4fdfcb5465a < 721cfeb0b9572084435695ae535411b921d1ea68affected
LinuxLinux6f6c3c36f0917be24587eeba818ab4fdfcb5465a < b4ef887bee4d3c177adac5d1eab8b2de31b08ac3affected
LinuxLinux6f6c3c36f0917be24587eeba818ab4fdfcb5465a < 0d58a70b6dc7b65772e3ef7c43beb91882cf9ed5affected
LinuxLinux6f6c3c36f0917be24587eeba818ab4fdfcb5465a < f51a540b14eecb8667bbe450192318271b87631eaffected
LinuxLinux6f6c3c36f0917be24587eeba818ab4fdfcb5465a < 09e4c486348e176c083f8bee9169ae8f408cf8d1affected
LinuxLinux6f6c3c36f0917be24587eeba818ab4fdfcb5465a < f12afefb7b01f94d6d66d397f323a9914edbf70eaffected
LinuxLinux5.1affected
LinuxLinux0 < 5.1unaffected
LinuxLinux5.10.266 <= 5.10.*unaffected
LinuxLinux5.15.217 <= 5.15.*unaffected
LinuxLinux6.1.184 <= 6.1.*unaffected
LinuxLinux6.6.153 <= 6.6.*unaffected
LinuxLinux6.12.105 <= 6.12.*unaffected
LinuxLinux6.18.46 <= 6.18.*unaffected
LinuxLinux7.1.10 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References