CVE-2026-98053
N/A
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: avs: Refactor and fix init_config access
Existing code accesses enties found in ->init_configs array through indexes that are part of ->config_ids array. Those two are limited by: ->num_init_configs and ->num_config_ids respectively. Using ID larger or equal to ->num_init_configs leads to out-of-bounds access:
avs_path_module_send_init_configs() loop: (…) &acomp->tplg->init_configs[ids[i]] ^ out-of-bounds candidate
Rather than adding another if-statement, refactor the code. There is no need to store the IDs, have a list of pointers to actual config-entries instead. As the verification of ->init_config entries does not differ from verification of other types that are part of the topology.c file, simply reuse the code.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Linux | Linux | 8a49ef789b1be68242624d460df2ada8087308a7 < 75bd5ea9c858d89fb8862f23afb00783bf02cd7a | affected |
| Linux | Linux | 8a49ef789b1be68242624d460df2ada8087308a7 < 8f20a0f4f7d638e83ae86db1719a24c7049762f5 | affected |
| Linux | Linux | 8a49ef789b1be68242624d460df2ada8087308a7 < 681e91035dc794896a904852040837190e5041f5 | affected |
| Linux | Linux | 6.9 | affected |
| Linux | Linux | 0 < 6.9 | unaffected |
| Linux | Linux | 6.18.53 <= 6.18.* | unaffected |
| Linux | Linux | 7.2.7 <= 7.2.* | unaffected |
| Linux | Linux | 7.3-rc3 <= * | unaffected |
Weaknesses
References
- https://git.kernel.org/stable/c/75bd5ea9c858d89fb8862f23afb00783bf02cd7a
- https://git.kernel.org/stable/c/8f20a0f4f7d638e83ae86db1719a24c7049762f5
- https://git.kernel.org/stable/c/681e91035dc794896a904852040837190e5041f5
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.