Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: tas2562: Validate values for volume writes

tas2562_volume_control_put() does not do any validation of the control
value written by userspace, it uses it to look up a value in a fixed
size array which can easily be overflowed and then writes whatever value
it gets back to the device. Add validation that we are loading a value
we have in the array.
Published: 2026-08-26
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

tas2562_volume_control_put() accepts a volume level supplied by userspace and uses it as an index into a fixed‑size array without validating the bounds. The unchecked index can exceed the array size, causing an out‑of‑bounds read and subsequently an out‑of‑bounds write to the TAS2562 audio codec. This memory corruption flaw is characterized by CWE-787. The effect is that an attacker can induce the driver to transmit malformed data, disrupting audio output or rendering the audio subsystem unusable, which constitutes a denial of service but does not provide arbitrary code execution.

Affected Systems

The vulnerability resides in the Linux kernel’s Advanced Sound Architecture driver for the TAS2562 codec. All kernel releases that incorporate this driver without the reported patch are affected. No specific kernel version numbers are listed; the issue applies to any build that includes the unvalidated volume write code.

Risk and Exploitability

The flaw operates in kernel mode and requires local access to the ALSA interface to issue volume control operations. Based on the description, the attack vector is inferred to be local, needing write permission to the audio control files. The CVSS score of 7.8 reflects a high impact on availability. The EPSS score of < 1 % indicates a low probability of automated exploitation. The vulnerability is not listed in the CISA KEV catalogue, and no public exploits are documented. While it does not grant arbitrary code execution, it can be leveraged to cause service disruption.

Generated by OpenCVE AI on August 28, 2026 at 19:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that includes the TAS2562 driver patch
  • If an immediate kernel update is not possible, blacklist or disable the tas2562 module to prevent the vulnerable code from loading
  • Restrict write access to the audio control files or device node so only privileged users can modify volume levels
  • Monitor system logs for abnormal volume control activity and review device permissions regularly

Generated by OpenCVE AI on August 28, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-125

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 27 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-125

Thu, 27 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Thu, 27 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129

Wed, 26 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2562: Validate values for volume writes tas2562_volume_control_put() does not do any validation of the control value written by userspace, it uses it to look up a value in a fixed size array which can easily be overflowed and then writes whatever value it gets back to the device. Add validation that we are loading a value we have in the array.
Title ASoC: tas2562: Validate values for volume writes
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-27T05:01:20.942Z

Reserved: 2026-08-26T14:34:25.764Z

Link: CVE-2026-80526

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T15:17:06.350

Modified: 2026-08-27T06:17:31.797

Link: CVE-2026-80526

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-26T00:00:00Z

Links: CVE-2026-80526 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:30:16Z

Weaknesses