Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: dapm: Fix off-by-one check on the second enum channel

The snd_soc_dapm_put_enum_double() rejects item[0] once it reaches
e->items, but it lets item[1] be equal to it. Both go on to
snd_soc_enum_item_to_val(), which indexes e->values with no bound of
its own, so an enum with a value table reads one element past the end.

The indexing arrived with the MUX consolidation, which relaxed the
item[1] check in the same hunk. The value MUX handler it deleted used
>= there, and the snd_soc_put_enum_double() in soc-ops.c still does.

Only adav80x pairs a value table with two shifts, and its second
channel looks accidental, but the control does report two values.
Writing three into it reads off the end of adav80x_mux_values. The
core catches that only under CONFIG_SND_CTL_INPUT_VALIDATION, which
defaults off.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Kernel memory disclosure through an out‑of‑bounds read in the ASoC audio subsystem
Action: Apply Patch
AI Analysis

Impact

The flaw is an off‑by‑one error in the ALSA System on a Chip (ASoC) sound subsystem. When a second enum channel value is processed, the code accepts an index that equals the number of items and then proceeds to read the values array without checking that the second index is within bounds. This can cause an out‑of‑bounds read of kernel memory containing audio control data. If an attacker can influence the value written to the control, they can read arbitrary kernel memory, potentially leaking sensitive information. The vulnerability is read‑only and does not allow code execution, but a memory disclosure could aid in privilege escalation.

Affected Systems

The defect exists in every Linux kernel release that has not incorporated the recent patch correcting the enum channel boundary check. All distributions and vendors that ship a kernel with the affected ASoC code paths are impacted, regardless of the specific version number.

Risk and Exploitability

The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local privilege or the ability to manipulate audio controls; the flaw is limited to reads, so the attack vector is likely local or available to users who have write access to sound controls. While the lack of public exploitation evidence reduces the immediate threat, the read‑out‑of‑bounds behavior still poses a moderate to potentially high risk in environments where audio controls are exposed to untrusted processes or networks. Prompt patching is therefore strongly recommended.

Generated by OpenCVE AI on September 20, 2026 at 04:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a Linux kernel version that includes the ASoC enum channel off‑by‑one fix
  • Enable the CONFIG_SND_CTL_INPUT_VALIDATION kernel configuration option to add an extra bounds check for audio controls
  • Restrict access to audio control interfaces by enforcing appropriate user permissions or disabling unused audio drivers

Generated by OpenCVE AI on September 20, 2026 at 04:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: dapm: Fix off-by-one check on the second enum channel The snd_soc_dapm_put_enum_double() rejects item[0] once it reaches e->items, but it lets item[1] be equal to it. Both go on to snd_soc_enum_item_to_val(), which indexes e->values with no bound of its own, so an enum with a value table reads one element past the end. The indexing arrived with the MUX consolidation, which relaxed the item[1] check in the same hunk. The value MUX handler it deleted used >= there, and the snd_soc_put_enum_double() in soc-ops.c still does. Only adav80x pairs a value table with two shifts, and its second channel looks accidental, but the control does report two values. Writing three into it reads off the end of adav80x_mux_values. The core catches that only under CONFIG_SND_CTL_INPUT_VALIDATION, which defaults off.
Title ASoC: dapm: Fix off-by-one check on the second enum channel
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:05:50.251Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90068

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:55.697

Modified: 2026-09-17T17:16:55.697

Link: CVE-2026-90068

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T05:00:13Z

Weaknesses