« Volver al listado

CVE-2026-90068

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

ASoC: dapm: Fix off-by-one check on the second enum channel

The snd_soc_dapm_put_enum_double() rejects item[0] once it reaches e->items, but it lets item[1] be equal to it. Both go on to snd_soc_enum_item_to_val(), which indexes e->values with no bound of its own, so an enum with a value table reads one element past the end.

The indexing arrived with the MUX consolidation, which relaxed the item[1] check in the same hunk. The value MUX handler it deleted used >= there, and the snd_soc_put_enum_double() in soc-ops.c still does.

Only adav80x pairs a value table with two shifts, and its second channel looks accidental, but the control does report two values. Writing three into it reads off the end of adav80x_mux_values.

Leer descripción completaMostrar menos

The core catches that only under CONFIG_SND_CTL_INPUT_VALIDATION, which defaults off.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-90068",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3727b4968453dbab8fe18f979d67285eb6b66801",
              "lessThan": "57ab955bde747327fb2042516ae1b7192c30e881",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3727b4968453dbab8fe18f979d67285eb6b66801",
              "lessThan": "806fa4e1f2bf73c54bc4b6360790ecc69d095ca5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3727b4968453dbab8fe18f979d67285eb6b66801",
              "lessThan": "496081b4edc1f6e662418831c5b14cddd8d7920c",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3727b4968453dbab8fe18f979d67285eb6b66801",
              "lessThan": "faf539af1a595a26e5a081a4e512caee2bc2f4c5",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3727b4968453dbab8fe18f979d67285eb6b66801",
              "lessThan": "32fc048391112559c34cb88d13594546939a4cd6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3727b4968453dbab8fe18f979d67285eb6b66801",
              "lessThan": "10a36512c21f861a03fba461a7ead09023df9c1b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3727b4968453dbab8fe18f979d67285eb6b66801",
              "lessThan": "55126ef66298e43c69f192acebae8c7cc0022cf6",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "3727b4968453dbab8fe18f979d67285eb6b66801",
              "lessThan": "14511c9b54ceeeef487409d73947c89ee8563590",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "sound/soc/soc-dapm.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "3.15"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "3.15",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.270",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.221",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.188",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.157",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.110",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.52",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.6",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc1",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "sound/soc/soc-dapm.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-09-17T17:16:55.697",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/10a36512c21f861a03fba461a7ead09023df9c1b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/14511c9b54ceeeef487409d73947c89ee8563590",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/32fc048391112559c34cb88d13594546939a4cd6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/496081b4edc1f6e662418831c5b14cddd8d7920c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/55126ef66298e43c69f192acebae8c7cc0022cf6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/57ab955bde747327fb2042516ae1b7192c30e881",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/806fa4e1f2bf73c54bc4b6360790ecc69d095ca5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/faf539af1a595a26e5a081a4e512caee2bc2f4c5",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: dapm: Fix off-by-one check on the second enum channel\n\nThe snd_soc_dapm_put_enum_double() rejects item[0] once it reaches\ne->items, but it lets item[1] be equal to it.  Both go on to\nsnd_soc_enum_item_to_val(), which indexes e->values with no bound of\nits own, so an enum with a value table reads one element past the end.\n\nThe indexing arrived with the MUX consolidation, which relaxed the\nitem[1] check in the same hunk.  The value MUX handler it deleted used\n>= there, and the snd_soc_put_enum_double() in soc-ops.c still does.\n\nOnly adav80x pairs a value table with two shifts, and its second\nchannel looks accidental, but the control does report two values.\nWriting three into it reads off the end of adav80x_mux_values.  The\ncore catches that only under CONFIG_SND_CTL_INPUT_VALIDATION, which\ndefaults off."
    }
  ],
  "lastModified": "2026-09-17T17:16:55.697",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}