« Volver al listado

CVE-2026-72300

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: topology: validate vendor array size before parsing

sof_parse_token_sets() reads array->size while iterating over topology private data. The loop condition only checks that some data remains, so a malformed topology with a truncated trailing vendor array can make the parser read the size field before a full vendor-array header is available.

Validate that the remaining private data contains a complete snd_soc_tplg_vendor_array header before reading array->size.

The declared array size check also needs to remain signed. asize is an int, but sizeof(*array) has type size_t, so comparing them directly promotes negative asize values to unsigned and lets them pass the check, as reported in the stable review thread reference below.

Leer descripción completaMostrar menos

Cast sizeof(*array) to int when validating the declared array size. This rejects negative, zero and otherwise too-small sizes before the parser dispatches to the tuple-specific code.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-72300",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5c37bd025068381f5bdbbf6a5ae3a1da8f6ed928",
              "lessThan": "7c6d2d2baeb1e62dc8c6951d27edc16c5ea6e3aa",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06d4938e41d62af7b5b3f39eb239f58b21f50443",
              "lessThan": "a40e250414b463e953c54cd2a829c9a9a49a78c3",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "55024322915539098f7a7dd318351c7a003ff041",
              "lessThan": "d34deef34c99bb4b3ebd2ac51058857827a20e7e",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "215e5fe75881a7e2425df04aeeed47a903d5cd5d",
              "lessThan": "201b60c4d15538fcc3c0c2ea9b75dd7d0f58022c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "215e5fe75881a7e2425df04aeeed47a903d5cd5d",
              "lessThan": "8468dd79cfb2ffbdeaf7c353f63d64941cb8ba05",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "756c48bdf23050def518e85929be6edea9ae6823",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "6.6.136",
              "lessThan": "6.6.145",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.12.83",
              "lessThan": "6.12.97",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.18.24",
              "lessThan": "6.18.40",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "6.19.14",
              "lessThan": "6.20",
              "versionType": "semver"
            }
          ],
          "programFiles": [
            "sound/soc/sof/topology.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.0"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.6.145",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.97",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.40",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.5",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/soc/sof/topology.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T06:22:02.690",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/201b60c4d15538fcc3c0c2ea9b75dd7d0f58022c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7c6d2d2baeb1e62dc8c6951d27edc16c5ea6e3aa",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8468dd79cfb2ffbdeaf7c353f63d64941cb8ba05",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a40e250414b463e953c54cd2a829c9a9a49a78c3",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/d34deef34c99bb4b3ebd2ac51058857827a20e7e",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: SOF: topology: validate vendor array size before parsing\n\nsof_parse_token_sets() reads array->size while iterating over topology\nprivate data. The loop condition only checks that some data remains, so a\nmalformed topology with a truncated trailing vendor array can make the\nparser read the size field before a full vendor-array header is available.\n\nValidate that the remaining private data contains a complete\nsnd_soc_tplg_vendor_array header before reading array->size.\n\nThe declared array size check also needs to remain signed. asize is an int,\nbut sizeof(*array) has type size_t, so comparing them directly promotes\nnegative asize values to unsigned and lets them pass the check,\nas reported in the stable review thread reference below.\n\nCast sizeof(*array) to int when validating the declared array size. This\nrejects negative, zero and otherwise too-small sizes before the parser\ndispatches to the tuple-specific code."
    }
  ],
  "lastModified": "2026-08-17T06:18:32.993",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}