Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put

In sof_ipc4_bytes_put(), the copy size is derived from the old
data->size in the buffer rather than the incoming new data's size
field from ucontrol. If the new data has a different size, the copy
uses the wrong length: it may truncate valid data or copy stale bytes.

Fix by validating and using the incoming data's sof_abi_hdr.size from
ucontrol before copying.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In the Linux kernel sound subsystem, a TOCTOU race causes the ioctl handler sof_ipc4_bytes_put() to copy buffer data using a stale size field from existing kernel data instead of the size supplied by user space. Because the copy length can be incorrect, the kernel may write beyond the intended bounds, truncating valid data or copying stale bytes. This flaw can corrupt kernel memory, disabling audio services or potentially causing a system crash.

Affected Systems

All Linux kernel releases that expose the ASoC synchronous firmware IPC4 control interface before the documented commit that validates the incoming size field are affected. Kernel versions that do not yet include the patch and still contain the old implementation are therefore vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while the EPSS score of <1% suggests exploitation is currently rare. The likely attack vector is local, requiring a user-space process to send IPC4 control messages. If an attacker can repeatedly trigger the race, they could corrupt kernel data, gain a denial of service, or potentially execute arbitrary code if a subsequent vulnerability is triggered. No known public exploit exists, and the vulnerability is not listed in CISA KEV.

Generated by OpenCVE AI on August 22, 2026 at 09:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest stable Linux kernel release that includes the commit validating the sof_abi_hdr.size field in sof_ipc4_bytes_put.
  • Reboot the system so that the updated kernel and any loaded modules use the corrected code.
  • If patching cannot be performed immediately, consider disabling the IPC4 control interface or limiting its exposure for users that do not require audio subsystem control.

Generated by OpenCVE AI on August 22, 2026 at 09:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-365

Wed, 19 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-805
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-365

Mon, 17 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-367

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put In sof_ipc4_bytes_put(), the copy size is derived from the old data->size in the buffer rather than the incoming new data's size field from ucontrol. If the new data has a different size, the copy uses the wrong length: it may truncate valid data or copy stale bytes. Fix by validating and using the incoming data's sof_abi_hdr.size from ucontrol before copying.
Title ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:42:37.543Z

Reserved: 2026-08-09T03:40:39.918Z

Link: CVE-2026-72304

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:03.120

Modified: 2026-08-17T06:18:33.467

Link: CVE-2026-72304

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72304 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T09:45:04Z

Weaknesses
  • CWE-805

    Buffer Access with Incorrect Length Value