Description
In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc4-topology: Return error for invalid number of formats

When the number of input or output formats is zero,
sof_ipc4_widget_setup_comp_src() and sof_ipc4_widget_setup_comp_asrc()
print an error and jump to the cleanup label. At that point 'ret' is
still 0, because the earlier sof_ipc4_get_audio_fmt() call succeeded, so
the function returns success and the caller never finds out that the
widget setup actually failed.

Set ret to -EINVAL before the goto so the error gets reported.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Audio configuration failure
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s ALSA System‑on‑Chip (ASoC) SOF IPC4 widget setup logic incorrectly reports success when the number of input or output formats is zero. Because the return value remains zero after a prior failure, callers assume the widget is set up correctly, leading to silent failures in audio configuration. This flaw represents improper error handling (CWE‑390) and does not directly enable privilege escalation or remote code execution, but it can degrade audio services or cause application instability.

Affected Systems

The vulnerability is present in all builds of the Linux kernel that include the affected ASoC SOF IPC4 widget code paths. Vendors that ship kernels without the patch may be impacted regardless of distribution or kernel version, as no specific release is identified in the data.

Risk and Exploitability

The EPSS score indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Attackers would need local kernel access or the ability to influence widget configuration to trigger the flaw, making it primarily an integrity or availability concern rather than a direct external threat.

Generated by OpenCVE AI on September 19, 2026 at 09:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Linux kernel to a version that includes the commit setting the return value to -EINVAL before cleanup.
  • If an update is not immediately possible, enforce application‑level checks on widget configuration results and handle failures explicitly, ensuring the caller receives the correct error code.
  • Schedule a kernel update when available and monitor audio service stability for any configuration anomalies.

Generated by OpenCVE AI on September 19, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Return error for invalid number of formats When the number of input or output formats is zero, sof_ipc4_widget_setup_comp_src() and sof_ipc4_widget_setup_comp_asrc() print an error and jump to the cleanup label. At that point 'ret' is still 0, because the earlier sof_ipc4_get_audio_fmt() call succeeded, so the function returns success and the caller never finds out that the widget setup actually failed. Set ret to -EINVAL before the goto so the error gets reported.
Title ASoC: SOF: ipc4-topology: Return error for invalid number of formats
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:12:12.795Z

Reserved: 2026-09-17T16:02:15.091Z

Link: CVE-2026-93187

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:14.787

Modified: 2026-09-17T17:18:14.787

Link: CVE-2026-93187

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:15:06Z

Weaknesses
  • CWE-390

    Detection of Error Condition Without Action