CVE-2026-90196

Summary

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: validate topology volume range before allocation

SOF treats the topology mixer min and max values as non-negative indices into its volume table. It stores them in signed fields, allocates max + 1 entries through an int argument, and later indexes the table with the stored range.

An inverted range is invalid, while a maximum at or above INT_MAX cannot be represented safely after the increment or in the signed fields. Validate the complete range before storing it or allocating the table.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux311ce4fe7637d96608b6e57bf9ebbd8aabcf429e < 992e130b888699d18da901b593d7a0fb75041a03affected
LinuxLinux311ce4fe7637d96608b6e57bf9ebbd8aabcf429e < cd63a1eb677e9548ba2d512be5dac4cb474ae145affected
LinuxLinux311ce4fe7637d96608b6e57bf9ebbd8aabcf429e < 8e1d63f5e272061208455b5aa4cc0d5bcbe5c1a8affected
LinuxLinux311ce4fe7637d96608b6e57bf9ebbd8aabcf429e < d2f41287b51a3261d447ae38000f7a6f5860663aaffected
LinuxLinux311ce4fe7637d96608b6e57bf9ebbd8aabcf429e < 72d0b77412aef2cec554cc84e176658f2a48dafaaffected
LinuxLinux311ce4fe7637d96608b6e57bf9ebbd8aabcf429e < a698e4a60fa54268a38f4e66378851a196cb139baffected
LinuxLinux5.2affected
LinuxLinux0 < 5.2unaffected
LinuxLinux6.1.188 <= 6.1.*unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References