Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: tegra: tegra210_ahub: Validate written enum value

tegra_ahub_put_value_enum() reads e->values[item[0]] before
checking whether item[0] is within the enum item range. The existing
check therefore happens too late to prevent an out-of-range read of the
values array.

Move the check before the array access.
Published: 2026-08-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Linux kernel tegra210_ahub driver contains a bug where the function tegra_ahub_put_value_enum() reads an element from the e->values array using an index supplied by the caller before verifying that the index is within the valid range. This out-of-bounds read is a kernel bounds check flaw and is listed as CWE‑1285, which can leak sensitive kernel memory contents to a local attacker. The flaw does not grant arbitrary code execution but may allow an attacker to view confidential data stored in the kernel, leading to information disclosure.

Affected Systems

The affected component is the tegra210_ahub driver in the Linux kernel for Tegra platforms. All releases that include this driver prior to the commit that relocates the bounds check are vulnerable. The fix is incorporated in the kernel source branches referenced in the provided commit URLs. Updating to a kernel that includes these commits resolves the issue.

Risk and Exploitability

The Exploit Prediction Scoring System calculates an EPSS below 1%, indicating a very low probability of exploitation. The CVSS score of 7.1 reflects a high severity, primarily due to the confidentiality impact. The vulnerability is not listed in the CISA KEV catalog. The exact attack vector is not explicitly described but would require the ability to cause the driver to process an out-of-range enumeration value, which typically would arise from a local user or a component with kernel privileges.

Generated by OpenCVE AI on August 22, 2026 at 02:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch that moves the bounds check before accessing the e->values array, using the commit(s) linked in the advisory to update the Linux kernel source and rebuild the system.
  • Reboot the system to load the updated tegra210_ahub driver.
  • If a kernel update cannot be applied immediately, blacklist or unload the tegra210_ahub module (e.g., modprobe -r tegra210_ahub or by adding it to /etc/modprobe.d/blacklist.conf) to prevent the driver from loading until the patch is applied.

Generated by OpenCVE AI on August 22, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 22 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Fri, 21 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1285
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 17 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Mon, 17 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Mon, 17 Aug 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H'}


Sat, 15 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Sat, 15 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: tegra: tegra210_ahub: Validate written enum value tegra_ahub_put_value_enum() reads e->values[item[0]] before checking whether item[0] is within the enum item range. The existing check therefore happens too late to prevent an out-of-range read of the values array. Move the check before the array access.
Title ASoC: tegra: tegra210_ahub: Validate written enum value
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-17T05:45:30.088Z

Reserved: 2026-08-15T05:44:03.881Z

Link: CVE-2026-74292

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T06:22:28.760

Modified: 2026-08-17T06:19:23.160

Link: CVE-2026-74292

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-15T00:00:00Z

Links: CVE-2026-74292 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T03:00:12Z

Weaknesses
  • CWE-1285

    Improper Validation of Specified Index, Position, or Offset in Input