CVE-2026-89943
8.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: loongson: Fix error handling in ACPI property parsing
In loongson_card_parse_acpi(), the return value of
device_property_read_string() for the codec-dai-name property was
ignored. If the property is missing or invalid, an uninitialized pointer
would be used later, potentially leading to undefined behavior.
Fix this by checking the return value and propagating the error appropriately.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | ddb538a3004b10a04a14a0d275c5f52a8d161e80 < 682c123cef455545f48ecbe74b3872fa303bf58f | affected |
| Linux | Linux | ddb538a3004b10a04a14a0d275c5f52a8d161e80 < 4e580d84a638f007b5b68d50d7633de502f325e7 | affected |
| Linux | Linux | ddb538a3004b10a04a14a0d275c5f52a8d161e80 < bb1602908c67db7197ab001638573262bccc6ca2 | affected |
| Linux | Linux | ddb538a3004b10a04a14a0d275c5f52a8d161e80 < 0eb0e3c623ac1da8b85d518043fef7660af7805d | affected |
| Linux | Linux | 6.12 | affected |
| Linux | Linux | 0 < 6.12 | unaffected |
| Linux | Linux | 6.12.110 <= 6.12.* | unaffected |
| Linux | Linux | 6.18.51 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.5 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc1 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/682c123cef455545f48ecbe74b3872fa303bf58f
- https://git.kernel.org/stable/c/4e580d84a638f007b5b68d50d7633de502f325e7
- https://git.kernel.org/stable/c/bb1602908c67db7197ab001638573262bccc6ca2
- https://git.kernel.org/stable/c/0eb0e3c623ac1da8b85d518043fef7660af7805d
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.