CVE-2026-23076
In the Linux kernel, the following vulnerability has been resolved:
ALSA: ctxfi: Fix potential OOB access in audio mixer handling
In the audio mixer handling code of ctxfi driver, the conf field is used as a kind of loop index, and it's referred in the index callbacks (amixer_index() and sum_index()).
As spotted recently by fuzzers, the current code causes OOB access at those functions. | UBSAN: array-index-out-of-bounds in /build/reproducible-path/linux-6.17.8/sound/pci/ctxfi/ctamixer.c:347:48 | index 8 is out of range for type 'unsigned char [8]'
After the analysis, the cause was found to be the lack of the proper (re-)initialization of conj field.
Leer descripción completaMostrar menos
This patch addresses those OOB accesses by adding the proper initializations of the loop indices.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
- Puntuación base: 7.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.15%
- Percentil entre todas las CVEs puntuadas: 3
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1059Command and Scripting Interpreterexecution75 %
Acceso local (AV:L) sin interacción de usuario permite escalada mediante desbordamiento de búfer en controlador ALSA. Ejecución de código como posible impacto tras elevar privilegios.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
CWE
- CWE-125
Referencias
- https://git.kernel.org/stable/c/61006c540cbdedea83b05577dc7fb7fa18fe1276
- https://git.kernel.org/stable/c/6524205326e0c1a21263b5c14e48e14ef7e449ae
- https://git.kernel.org/stable/c/873e2360d247eeee642878fcc3398babff7e387c
- https://git.kernel.org/stable/c/8c1d09806e1441bc6a54b9a4f2818918046d5174
- https://git.kernel.org/stable/c/a8c42d11b0526a89192bd2f79facb4c60c8a1f38
- https://git.kernel.org/stable/c/afca7ff5d5d4d63a1acb95461f55ca9a729feedf
- https://git.kernel.org/stable/c/d77ba72558cd66704f0fb7e0969f697e87c0f71c
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-23076",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-23076",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-10T20:42:28.584114Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.1,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "8cc72361481f00253f1e468ade5795427386d593",
"lessThan": "6524205326e0c1a21263b5c14e48e14ef7e449ae",
"versionType": "git"
},
{
"status": "affected",
"version": "8cc72361481f00253f1e468ade5795427386d593",
"lessThan": "afca7ff5d5d4d63a1acb95461f55ca9a729feedf",
"versionType": "git"
},
{
"status": "affected",
"version": "8cc72361481f00253f1e468ade5795427386d593",
"lessThan": "8c1d09806e1441bc6a54b9a4f2818918046d5174",
"versionType": "git"
},
{
"status": "affected",
"version": "8cc72361481f00253f1e468ade5795427386d593",
"lessThan": "a8c42d11b0526a89192bd2f79facb4c60c8a1f38",
"versionType": "git"
},
{
"status": "affected",
"version": "8cc72361481f00253f1e468ade5795427386d593",
"lessThan": "d77ba72558cd66704f0fb7e0969f697e87c0f71c",
"versionType": "git"
},
{
"status": "affected",
"version": "8cc72361481f00253f1e468ade5795427386d593",
"lessThan": "873e2360d247eeee642878fcc3398babff7e387c",
"versionType": "git"
},
{
"status": "affected",
"version": "8cc72361481f00253f1e468ade5795427386d593",
"lessThan": "61006c540cbdedea83b05577dc7fb7fa18fe1276",
"versionType": "git"
}
],
"programFiles": [
"sound/pci/ctxfi/ctamixer.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "2.6.31"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "2.6.31",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.249",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.199",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.162",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.122",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.68",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.8",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "6.19",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/pci/ctxfi/ctamixer.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-02-04T17:16:18.340",
"references": [
{
"url": "https://git.kernel.org/stable/c/61006c540cbdedea83b05577dc7fb7fa18fe1276",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6524205326e0c1a21263b5c14e48e14ef7e449ae",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/873e2360d247eeee642878fcc3398babff7e387c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/8c1d09806e1441bc6a54b9a4f2818918046d5174",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a8c42d11b0526a89192bd2f79facb4c60c8a1f38",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/afca7ff5d5d4d63a1acb95461f55ca9a729feedf",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/d77ba72558cd66704f0fb7e0969f697e87c0f71c",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: ctxfi: Fix potential OOB access in audio mixer handling\n\nIn the audio mixer handling code of ctxfi driver, the conf field is\nused as a kind of loop index, and it's referred in the index callbacks\n(amixer_index() and sum_index()).\n\nAs spotted recently by fuzzers, the current code causes OOB access at\nthose functions.\n| UBSAN: array-index-out-of-bounds in /build/reproducible-path/linux-6.17.8/sound/pci/ctxfi/ctamixer.c:347:48\n| index 8 is out of range for type 'unsigned char [8]'\n\nAfter the analysis, the cause was found to be the lack of the proper\n(re-)initialization of conj field.\n\nThis patch addresses those OOB accesses by adding the proper\ninitializations of the loop indices."
},
{
"lang": "es",
"value": "En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:\n\nALSA: ctxfi: Corrección de posible acceso OOB en el manejo del mezclador de audio\n\nEn el código de manejo del mezclador de audio del controlador ctxfi, el campo 'conf' se utiliza como una especie de índice de bucle, y se hace referencia a él en las retrollamadas de índice (amixer_index() y sum_index()).\n\nComo fue detectado recientemente por fuzzers, el código actual causa acceso OOB en esas funciones.\n| UBSAN: índice de array fuera de límites en /build/reproducible-path/linux-6.17.8/sound/pci/ctxfi/ctamixer.c:347:48\n| el índice 8 está fuera de rango para el tipo 'unsigned char [8]'\n\nDespués del análisis, se encontró que la causa era la falta de la inicialización (o reinicialización) adecuada del campo 'conj'.\n\nEste parche aborda esos accesos OOB añadiendo las inicializaciones adecuadas de los índices de bucle."
}
],
"lastModified": "2026-06-17T10:20:49.340",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "16C29C42-76B1-4C84-A250-DE57F1D5FE82",
"versionEndExcluding": "5.10.249",
"versionStartIncluding": "2.6.31"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A247FBA6-BEB9-484F-B892-DD5517949CCD",
"versionEndExcluding": "5.15.199",
"versionStartIncluding": "5.11"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6579E0D4-0641-479D-A4C3-0EF618798C55",
"versionEndExcluding": "6.1.162",
"versionStartIncluding": "5.16"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8EAAE395-0162-4BAF-9AD5-E9AF3C869C4F",
"versionEndExcluding": "6.6.122",
"versionStartIncluding": "6.2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "52F38E19-0FDD-4992-9D6D-D4169D689598",
"versionEndExcluding": "6.12.68",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E65C6E79-7EBE-4C77-93F0-818CF5B38F4E",
"versionEndExcluding": "6.18.8",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "17B67AA7-40D6-4AFA-8459-F200F3D7CFD1"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C47E4CC9-C826-4FA9-B014-7FE3D9B318B2"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F71D92C0-C023-48BD-B3B6-70B638EEE298"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "13580667-0A98-40CC-B29F-D12790B91BDB"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAD1FED7-CF48-47BF-AC7D-7B6FA3C065FC"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3EF854A1-ABB1-4E93-BE9A-44569EC76C0D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}