Description
In the Linux kernel, the following vulnerability has been resolved:

soundwire: fix bug in sdw_add_element_group_count found by syzkaller

The original implementation caused an out-of-bounds memory access
in the sdw_add_element_group_count for-loop when i == num.

for (i = 0; i <= num; i++) {
if (rate == group->rates[i] && lane == group->lanes[i])
...

To fix this error, the function now checks for existing rate/lane
entries in the group(a function parameter) using a for-loop before
adding them.

No functional changes apart from this fix.
Published: 2026-08-15
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The bug existed in the function that adds element groups to the soundwire driver, where a loop erroneously iterated one time too many, allowing an array index to exceed the bounds of the group->rates and group->lanes arrays. This out‑of‑bounds memory access could corrupt kernel memory, potentially leading to kernel crashes, information disclosure, or local privilege escalation, depending on the attacker’s context.

Affected Systems

All Linux kernels containing the soundwire driver that have not yet incorporated the commit that fixes the off‑by‑one loop are at risk. The patch is part of the mainline kernel and is present in any kernel release built after the referenced commit. Kernels built before the fix remain vulnerable.

Risk and Exploitability

Based on the nature of kernel memory‑corruption flaws, it is inferred that the vulnerability could be triggered by a local attacker who can interact with the soundwire driver (for example, by loading the module, sending control commands, or manipulating device parameters). The CVSS score is 7.8. The EPSS score is listed as less than 1 % and the vulnerability is not included in CISA’s KEV catalog, indicating a low publicly known exploitation probability at present. Nevertheless, kernel memory‑corruption bugs have historically posed high exploitation risk if not patched. The correct mitigations are to update the kernel or otherwise prevent exploitation of the affected driver.

Generated by OpenCVE AI on August 22, 2026 at 05:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a kernel version that includes the patched soundwire driver
  • If a kernel upgrade is not immediately possible, obtain and apply the patch from the commit identified by the Git kernel link (e.g., the commit checksum a454f61747c97e2eadaa7a35ffc1f4b1645c6a53) and rebuild the kernel
  • If Soundwire functionality is not required, blacklist or remove the snd‑soundwire module to eliminate the vulnerable code

Generated by OpenCVE AI on August 22, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Thu, 20 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1285
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787

Mon, 17 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Sat, 15 Aug 2026 19:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 15 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: soundwire: fix bug in sdw_add_element_group_count found by syzkaller The original implementation caused an out-of-bounds memory access in the sdw_add_element_group_count for-loop when i == num. for (i = 0; i <= num; i++) { if (rate == group->rates[i] && lane == group->lanes[i]) ... To fix this error, the function now checks for existing rate/lane entries in the group(a function parameter) using a for-loop before adding them. No functional changes apart from this fix.
Title soundwire: fix bug in sdw_add_element_group_count found by syzkaller
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:44:50.041Z

Reserved: 2026-08-09T03:40:39.936Z

Link: CVE-2026-72488

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:23.087

Modified: 2026-08-17T06:19:17.037

Link: CVE-2026-72488

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-72488 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T06:00:11Z

Weaknesses
  • CWE-1285

    Improper Validation of Specified Index, Position, or Offset in Input