Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: validate topology volume range before allocation

SOF treats the topology mixer min and max values as non-negative indices
into its volume table. It stores them in signed fields, allocates max + 1
entries through an int argument, and later indexes the table with the
stored range.

An inverted range is invalid, while a maximum at or above INT_MAX cannot
be represented safely after the increment or in the signed fields.
Validate the complete range before storing it or allocating the table.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel’s ASoC: SOF audio subsystem, the topology mixer records minimum and maximum volume indices in signed fields. The code allocates a table of size "max + 1" based on these values and later indexes the table with the stored range. If an inverted range or a maximum value close to INT_MAX is supplied, the allocation can overflow and the indices may fall outside the allocated memory, leading to memory corruption that can crash the kernel. This loss of stability manifests as a denial of service.

Affected Systems

All Linux kernel builds that contain the ASoC: SOF audio subsystem and lack the fix introduced by commit 72d0b77412aef2cec554cc84e176658f2a48dafa are potentially affected. Since the patch applies to all kernel versions prior to that commit, any system running an unpatched kernel that includes the SOF audio module is vulnerable.

Risk and Exploitability

E​PSS indicates a probability of exploitation that is less than 1 %, and the vulnerability is not listed in the CISA KEV catalog, suggesting a low current exploitation risk. The kernel context and lack of a public CVSS score imply that local exploitation may require an attacker to influence the topology configuration, such as by loading a malicious or improperly configured driver. This is inferred from the description because the exact attack vector is not explicitly detailed in the CVE entry. The likely attack vector is local privileged code that configures invalid audio parameters, but this is not confirmed in the advisory.

Generated by OpenCVE AI on September 20, 2026 at 01:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel update that includes commit 72d0b77412aef2cec554cc84e176658f2a48dafa or later.
  • If an immediate kernel update is not possible, unload or disable the affected ASoC: SOF audio driver until the patch is applied.
  • Review and modify any custom or third‑party audio drivers or user‑space utilities that supply topology volume ranges to ensure they validate min/max bounds before passing them to the kernel.

Generated by OpenCVE AI on September 20, 2026 at 01:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sun, 20 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-119
CWE-190

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: validate topology volume range before allocation SOF treats the topology mixer min and max values as non-negative indices into its volume table. It stores them in signed fields, allocates max + 1 entries through an int argument, and later indexes the table with the stored range. An inverted range is invalid, while a maximum at or above INT_MAX cannot be represented safely after the increment or in the signed fields. Validate the complete range before storing it or allocating the table.
Title ASoC: SOF: validate topology volume range before allocation
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:07:15.610Z

Reserved: 2026-09-11T19:38:34.792Z

Link: CVE-2026-90196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:14.400

Modified: 2026-09-17T17:17:14.400

Link: CVE-2026-90196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T01:45:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-190

    Integer Overflow or Wraparound