« Volver al listado

CVE-2026-72257

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback

When q6apm_free_fragments() is called it frees rx_data.buf/tx_data.buf and sets them to NULL under graph->lock. A late DSP buffer-done response can race with this: graph_callback() passes the !graph->ar_graph guard (not yet NULL), acquires the lock, but then dereferences a now-NULL buf pointer to read buf[token].phys, crashing at virtual address 0x10.

Add a NULL check for buf inside the mutex-protected section in both the write-done (DATA_CMD_RSP_WR_SH_MEM_EP_DATA_BUFFER_DONE_V2) and read-done (DATA_CMD_RSP_RD_SH_MEM_EP_DATA_BUFFER_V2) handlers and bail out cleanly if buffers have already been freed.

Leer descripción completaMostrar menos

This problem is only shown up recently while apr bus was updated to process the commands per service rather from single global queue.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72257",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5477518b8a0e8a45239646acd80c9bafc4401522",
              "lessThan": "a164e744d8de1c41049bd9a1452a4b6bbf5bd8bc",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5477518b8a0e8a45239646acd80c9bafc4401522",
              "lessThan": "ec369eac0795cfa8f4d3a0cd35a1e8e15f780331",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5477518b8a0e8a45239646acd80c9bafc4401522",
              "lessThan": "2c715f8a1e644ce4c3e8be5b0fd3f1f4704b73b3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5477518b8a0e8a45239646acd80c9bafc4401522",
              "lessThan": "ca028334343a140efda4b22e53cbce2c5e94a489",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5477518b8a0e8a45239646acd80c9bafc4401522",
              "lessThan": "214af790e3a33ab73587de4c925c60a550eae9c6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "5477518b8a0e8a45239646acd80c9bafc4401522",
              "lessThan": "2e9261761b35f0b67b7487688cd1365f535be0b3",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/soc/qcom/qdsp6/q6apm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.16"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.16",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.1.178",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/soc/qcom/qdsp6/q6apm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:21:53.527",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/214af790e3a33ab73587de4c925c60a550eae9c6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2c715f8a1e644ce4c3e8be5b0fd3f1f4704b73b3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/2e9261761b35f0b67b7487688cd1365f535be0b3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a164e744d8de1c41049bd9a1452a4b6bbf5bd8bc",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ca028334343a140efda4b22e53cbce2c5e94a489",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/ec369eac0795cfa8f4d3a0cd35a1e8e15f780331",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback\n\nWhen q6apm_free_fragments() is called it frees rx_data.buf/tx_data.buf\nand sets them to NULL under graph->lock. A late DSP buffer-done response\ncan race with this: graph_callback() passes the !graph->ar_graph guard\n(not yet NULL), acquires the lock, but then dereferences a now-NULL buf\npointer to read buf[token].phys, crashing at virtual address 0x10.\n\nAdd a NULL check for buf inside the mutex-protected section in both the\nwrite-done (DATA_CMD_RSP_WR_SH_MEM_EP_DATA_BUFFER_DONE_V2) and\nread-done (DATA_CMD_RSP_RD_SH_MEM_EP_DATA_BUFFER_V2) handlers and bail\nout cleanly if buffers have already been freed.\n\nThis problem is only shown up recently while apr bus was updated to\nprocess the commands per service rather from single global queue."
    }
  ],
  "lastModified": "2026-08-17T06:18:28.020",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}