CVE-2026-80910
In the Linux kernel, the following vulnerability has been resolved:
ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses
EAR SPKR PA Gain" and the four "WSA RX* Mux" controls are enumerated, but their get and put callbacks access the value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int).
This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type") and commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of bounds for enum type"), but wsa-macro was missed.
Leer descripción completaMostrar menos
On 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value sanity check and every read of these controls fails with -EINVAL.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/2fe7a89b2b5b73be35c1e493d0246314ba54e427
- https://git.kernel.org/stable/c/4bcac4bf304a3ec746192e49a669c236aaf27dbf
- https://git.kernel.org/stable/c/524aa7b9954b0a43dd13f71ecbbac52a151c326d
- https://git.kernel.org/stable/c/56f24311fd5607588a47e44675195a9efb200f29
- https://git.kernel.org/stable/c/7bcdde412e6c744f6135e02b12a735e2e37b639f
- https://git.kernel.org/stable/c/891129df5de79cd533ae335c6eab24df2ff2b0fd
- https://git.kernel.org/stable/c/bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80910",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"lessThan": "bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d",
"versionType": "git"
},
{
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"lessThan": "4bcac4bf304a3ec746192e49a669c236aaf27dbf",
"versionType": "git"
},
{
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"lessThan": "891129df5de79cd533ae335c6eab24df2ff2b0fd",
"versionType": "git"
},
{
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"lessThan": "524aa7b9954b0a43dd13f71ecbbac52a151c326d",
"versionType": "git"
},
{
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"lessThan": "2fe7a89b2b5b73be35c1e493d0246314ba54e427",
"versionType": "git"
},
{
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"lessThan": "7bcdde412e6c744f6135e02b12a735e2e37b639f",
"versionType": "git"
},
{
"status": "affected",
"version": "809bcbcecebff86003e13f07444d21b9d6652a64",
"lessThan": "56f24311fd5607588a47e44675195a9efb200f29",
"versionType": "git"
}
],
"programFiles": [
"sound/soc/codecs/lpass-wsa-macro.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.11"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.11",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/soc/codecs/lpass-wsa-macro.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-04T18:18:00.783",
"references": [
{
"url": "https://git.kernel.org/stable/c/2fe7a89b2b5b73be35c1e493d0246314ba54e427",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4bcac4bf304a3ec746192e49a669c236aaf27dbf",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/524aa7b9954b0a43dd13f71ecbbac52a151c326d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/56f24311fd5607588a47e44675195a9efb200f29",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7bcdde412e6c744f6135e02b12a735e2e37b639f",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/891129df5de79cd533ae335c6eab24df2ff2b0fd",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses\n\nEAR SPKR PA Gain\" and the four \"WSA RX* Mux\" controls are enumerated,\nbut their get and put callbacks access the value through\nucontrol->value.integer.value[0] (a long) instead of\nucontrol->value.enumerated.item[0] (an unsigned int).\n\nThis same pattern was fixed in the sibling drivers by\ncommit bcfe5f76cc40 (\"ASoC: codecs: rx-macro: fix accessing array\nout of bounds for enum type\") and\ncommit 0ea5eff7c606 (\"ASoC: codecs: va-macro: fix accessing array\nout of bounds for enum type\"), but wsa-macro was missed.\n\nOn 64-bit kernels with CONFIG_SND_CTL_DEBUG this trips the elem value\nsanity check and every read of these controls fails with -EINVAL."
}
],
"lastModified": "2026-09-04T18:18:00.783",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}