CVE-2026-72257
In the Linux kernel, the following vulnerability has been resolved:
ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback
When q6apm_free_fragments() is called it frees rx_data.buf/tx_data.buf and sets them to NULL under graph->lock. A late DSP buffer-done response can race with this: graph_callback() passes the !graph->ar_graph guard (not yet NULL), acquires the lock, but then dereferences a now-NULL buf pointer to read buf[token].phys, crashing at virtual address 0x10.
Add a NULL check for buf inside the mutex-protected section in both the write-done (DATA_CMD_RSP_WR_SH_MEM_EP_DATA_BUFFER_DONE_V2) and read-done (DATA_CMD_RSP_RD_SH_MEM_EP_DATA_BUFFER_V2) handlers and bail out cleanly if buffers have already been freed.
Leer descripción completaMostrar menos
This problem is only shown up recently while apr bus was updated to process the commands per service rather from single global queue.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/214af790e3a33ab73587de4c925c60a550eae9c6
- https://git.kernel.org/stable/c/2c715f8a1e644ce4c3e8be5b0fd3f1f4704b73b3
- https://git.kernel.org/stable/c/2e9261761b35f0b67b7487688cd1365f535be0b3
- https://git.kernel.org/stable/c/a164e744d8de1c41049bd9a1452a4b6bbf5bd8bc
- https://git.kernel.org/stable/c/ca028334343a140efda4b22e53cbce2c5e94a489
- https://git.kernel.org/stable/c/ec369eac0795cfa8f4d3a0cd35a1e8e15f780331
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72257",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5477518b8a0e8a45239646acd80c9bafc4401522",
"lessThan": "a164e744d8de1c41049bd9a1452a4b6bbf5bd8bc",
"versionType": "git"
},
{
"status": "affected",
"version": "5477518b8a0e8a45239646acd80c9bafc4401522",
"lessThan": "ec369eac0795cfa8f4d3a0cd35a1e8e15f780331",
"versionType": "git"
},
{
"status": "affected",
"version": "5477518b8a0e8a45239646acd80c9bafc4401522",
"lessThan": "2c715f8a1e644ce4c3e8be5b0fd3f1f4704b73b3",
"versionType": "git"
},
{
"status": "affected",
"version": "5477518b8a0e8a45239646acd80c9bafc4401522",
"lessThan": "ca028334343a140efda4b22e53cbce2c5e94a489",
"versionType": "git"
},
{
"status": "affected",
"version": "5477518b8a0e8a45239646acd80c9bafc4401522",
"lessThan": "214af790e3a33ab73587de4c925c60a550eae9c6",
"versionType": "git"
},
{
"status": "affected",
"version": "5477518b8a0e8a45239646acd80c9bafc4401522",
"lessThan": "2e9261761b35f0b67b7487688cd1365f535be0b3",
"versionType": "git"
}
],
"programFiles": [
"sound/soc/qcom/qdsp6/q6apm.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.16"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.16",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/soc/qcom/qdsp6/q6apm.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-15T06:21:53.527",
"references": [
{
"url": "https://git.kernel.org/stable/c/214af790e3a33ab73587de4c925c60a550eae9c6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2c715f8a1e644ce4c3e8be5b0fd3f1f4704b73b3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/2e9261761b35f0b67b7487688cd1365f535be0b3",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a164e744d8de1c41049bd9a1452a4b6bbf5bd8bc",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ca028334343a140efda4b22e53cbce2c5e94a489",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ec369eac0795cfa8f4d3a0cd35a1e8e15f780331",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback\n\nWhen q6apm_free_fragments() is called it frees rx_data.buf/tx_data.buf\nand sets them to NULL under graph->lock. A late DSP buffer-done response\ncan race with this: graph_callback() passes the !graph->ar_graph guard\n(not yet NULL), acquires the lock, but then dereferences a now-NULL buf\npointer to read buf[token].phys, crashing at virtual address 0x10.\n\nAdd a NULL check for buf inside the mutex-protected section in both the\nwrite-done (DATA_CMD_RSP_WR_SH_MEM_EP_DATA_BUFFER_DONE_V2) and\nread-done (DATA_CMD_RSP_RD_SH_MEM_EP_DATA_BUFFER_V2) handlers and bail\nout cleanly if buffers have already been freed.\n\nThis problem is only shown up recently while apr bus was updated to\nprocess the commands per service rather from single global queue."
}
],
"lastModified": "2026-08-17T06:18:28.020",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}