Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc

In sof_ipc3_control_update(), the expected_size calculation uses
firmware-provided cdata->num_elems in arithmetic that could overflow
on 32-bit platforms, wrapping to a small value. This would allow the
cdata->rhdr.hdr.size comparison to pass with mismatched sizes,
potentially leading to out-of-bounds access in snd_sof_update_control.

Use check_mul_overflow() and check_add_overflow() to detect and reject
overflowed size calculations.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel, an integer overflow in the SOF ipc3 control update path allows a crafted firmware message to compute a small buffer size. This lets the size check in the driver pass while the actual data written exceeds the allocated buffer, causing an out-of-bounds access in the host audio driver. The flaw can corrupt kernel memory or trigger a crash. Based on this, it is inferred that a local user with the ability to load or influence firmware might potentially gain elevated privileges or destabilize the system.

Affected Systems

All 32‑bit Linux kernel builds that support the ASoC SOF ipc3 control path are affected. The vulnerability is present until the patch is applied, affecting any machine that loads SOF firmware with an unbounded cdata->num_elems field.

Risk and Exploitability

Based on the description, exploitation would require kernel-level access to supply malicious firmware or modify the control update packet. A privileged local user could achieve this. The CVSS score is 7.8, indicating high severity. While the EPSS score is low at < 1% and the vulnerability is not listed in KEV, the kernel-level nature and potential for arbitrary memory corruption give this flaw a high risk, making immediate remediation essential.

Generated by OpenCVE AI on August 17, 2026 at 19:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest kernel update that includes the integer-overflow check patch for the SOF ipc3 control update path
  • If an immediate kernel upgrade is not feasible, restrict firmware loading to signed and verified images and revoke access to untrusted firmware management interfaces
  • Consider disabling the SOF ipc3 control path or disabling loading of SOF firmware on systems that do not require the feature to eliminate the vulnerable code path

Generated by OpenCVE AI on August 17, 2026 at 19:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 00:15:00 +0000


Mon, 17 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Mon, 17 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-680

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc In sof_ipc3_control_update(), the expected_size calculation uses firmware-provided cdata->num_elems in arithmetic that could overflow on 32-bit platforms, wrapping to a small value. This would allow the cdata->rhdr.hdr.size comparison to pass with mismatched sizes, potentially leading to out-of-bounds access in snd_sof_update_control. Use check_mul_overflow() and check_add_overflow() to detect and reject overflowed size calculations.
Title ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:42:34.654Z

Reserved: 2026-08-09T03:40:39.918Z

Link: CVE-2026-72302

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:02.917

Modified: 2026-08-17T06:18:33.227

Link: CVE-2026-72302

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72302 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T19:45:04Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write