Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc4-control: Validate notification payload size

Validate MODULE_NOTIFICATION payload length before reading
bytes/channel data in control update handling.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

During control update handling in the ASoC SOF ipc4-control subsystem, the kernel does not verify the length of incoming MODULE_NOTIFICATION payloads before reading them. This omission means that a payload larger than the expected size could be read beyond the intended buffer boundary. The consequence is potentially undefined behavior that could compromise kernel stability.

Affected Systems

Affected systems include any installations of the Linux kernel that incorporate the ASoC SOF ipc4-control subsystem. Since the patch is in the official kernel source, all kernels released before the inclusion of commit 5bdfeccb7fbf6e000fc783cd8412732e67c1ad0c are potentially vulnerable. No specific kernel version range is listed in the CVE data, but any kernel prior to this commit could be impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity, while the EPSS score of < 1% suggests a low probability of current exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known public exploits. Based on the description, it is inferred that the attack vector requires a local environment where an attacker can deliver a crafted MODULE_NOTIFICATION payload to the kernel module.

Generated by OpenCVE AI on August 17, 2026 at 20:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply a kernel update that includes the commit 5bdfeccb7fbf6e000fc783cd8412732e67c1ad0c.
  • If a patched kernel is unavailable, disable the ASoC SOF ipc4-control subsystem to prevent processing of MODULE_NOTIFICATION messages.
  • Enforce module signing and restrict loading of untrusted modules to limit interactions with the vulnerable subsystem.

Generated by OpenCVE AI on August 17, 2026 at 20:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 00:15:00 +0000


Mon, 17 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-20

Mon, 17 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-787

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Validate notification payload size Validate MODULE_NOTIFICATION payload length before reading bytes/channel data in control update handling.
Title ASoC: SOF: ipc4-control: Validate notification payload size
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:42:35.730Z

Reserved: 2026-08-09T03:40:39.918Z

Link: CVE-2026-72303

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:03.023

Modified: 2026-08-17T06:18:33.357

Link: CVE-2026-72303

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72303 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T20:15:06Z

Weaknesses