Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: loongson: Fix error handling in ACPI property parsing

In loongson_card_parse_acpi(), the return value of
device_property_read_string() for the `codec-dai-name` property was
ignored. If the property is missing or invalid, an uninitialized pointer
would be used later, potentially leading to undefined behavior.

Fix this by checking the return value and propagating the error
appropriately.
Published: 2026-09-16
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Kernel Crash
Action: Apply Patch
AI Analysis

Impact

The loongson ALSA driver in the Linux kernel contains a flaw in the ACPI property parsing routine. In the function loongson_card_parse_acpi(), the return value of device_property_read_string() is ignored when reading the codec-dai-name property. When this property is missing or malformed, the driver subsequently dereferences an uninitialized pointer, which can lead to undefined behavior such as a kernel crash or memory corruption. This flaw is a use‑of‑uninitialized‑variable weakness that undermines kernel stability.

Affected Systems

All Linux kernels that include the loongson ALSA driver are affected. The vulnerability exists in any distro or custom kernel that compiles the loongson driver, as the issue is in the kernel source and not addressed by specific patch versions in the CVE description. The exact release versions are not specified, so any kernel containing the loongson driver without the applied fix is vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates high severity, yet the EPSS score of less than 1 % suggests a very low probability of exploitation at this time. The issue is not listed in the CISA KEV catalog, implying no widespread incidents are known. Exploitation would require manipulation of ACPI properties during device initialization, which the likely attack vector is local or pre‑boot access on the target system. Because the flaw induces undefined behavior rather than an attacker‑controlled payload, the primary impact is a denial of service via kernel panic rather than privilege escalation. Therefore, while the theoretical impact is high, the realistic exploitation risk remains low until an attacker can modify ACPI firmware or utilize a local exploit during boot.

Generated by OpenCVE AI on September 18, 2026 at 08:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel version that includes the commit fixing loongson ACPI property parsing (e.g., kernel commit 0eb0e3c7).
  • If an immediate kernel upgrade is not possible, temporarily disable or unload the loongson driver until the patch can be applied to avoid dereferencing the invalid pointer.
  • Monitor system logs for kernel panics or abnormal behavior related to ACPI property parsing and apply the patch promptly when the driver is in use.

Generated by OpenCVE AI on September 18, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Fri, 18 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-457

Wed, 16 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 16 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: loongson: Fix error handling in ACPI property parsing In loongson_card_parse_acpi(), the return value of device_property_read_string() for the `codec-dai-name` property was ignored. If the property is missing or invalid, an uninitialized pointer would be used later, potentially leading to undefined behavior. Fix this by checking the return value and propagating the error appropriately.
Title ASoC: loongson: Fix error handling in ACPI property parsing
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-16T14:40:31.281Z

Reserved: 2026-09-11T19:38:34.777Z

Link: CVE-2026-89943

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-16T11:17:03.993

Modified: 2026-09-16T15:18:19.700

Link: CVE-2026-89943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T09:00:08Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable