CVE-2026-90068
In the Linux kernel, the following vulnerability has been resolved:
ASoC: dapm: Fix off-by-one check on the second enum channel
The snd_soc_dapm_put_enum_double() rejects item[0] once it reaches e->items, but it lets item[1] be equal to it. Both go on to snd_soc_enum_item_to_val(), which indexes e->values with no bound of its own, so an enum with a value table reads one element past the end.
The indexing arrived with the MUX consolidation, which relaxed the item[1] check in the same hunk. The value MUX handler it deleted used >= there, and the snd_soc_put_enum_double() in soc-ops.c still does.
Only adav80x pairs a value table with two shifts, and its second channel looks accidental, but the control does report two values. Writing three into it reads off the end of adav80x_mux_values.
Leer descripción completaMostrar menos
The core catches that only under CONFIG_SND_CTL_INPUT_VALIDATION, which defaults off.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/10a36512c21f861a03fba461a7ead09023df9c1b
- https://git.kernel.org/stable/c/14511c9b54ceeeef487409d73947c89ee8563590
- https://git.kernel.org/stable/c/32fc048391112559c34cb88d13594546939a4cd6
- https://git.kernel.org/stable/c/496081b4edc1f6e662418831c5b14cddd8d7920c
- https://git.kernel.org/stable/c/55126ef66298e43c69f192acebae8c7cc0022cf6
- https://git.kernel.org/stable/c/57ab955bde747327fb2042516ae1b7192c30e881
- https://git.kernel.org/stable/c/806fa4e1f2bf73c54bc4b6360790ecc69d095ca5
- https://git.kernel.org/stable/c/faf539af1a595a26e5a081a4e512caee2bc2f4c5
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-90068",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3727b4968453dbab8fe18f979d67285eb6b66801",
"lessThan": "57ab955bde747327fb2042516ae1b7192c30e881",
"versionType": "git"
},
{
"status": "affected",
"version": "3727b4968453dbab8fe18f979d67285eb6b66801",
"lessThan": "806fa4e1f2bf73c54bc4b6360790ecc69d095ca5",
"versionType": "git"
},
{
"status": "affected",
"version": "3727b4968453dbab8fe18f979d67285eb6b66801",
"lessThan": "496081b4edc1f6e662418831c5b14cddd8d7920c",
"versionType": "git"
},
{
"status": "affected",
"version": "3727b4968453dbab8fe18f979d67285eb6b66801",
"lessThan": "faf539af1a595a26e5a081a4e512caee2bc2f4c5",
"versionType": "git"
},
{
"status": "affected",
"version": "3727b4968453dbab8fe18f979d67285eb6b66801",
"lessThan": "32fc048391112559c34cb88d13594546939a4cd6",
"versionType": "git"
},
{
"status": "affected",
"version": "3727b4968453dbab8fe18f979d67285eb6b66801",
"lessThan": "10a36512c21f861a03fba461a7ead09023df9c1b",
"versionType": "git"
},
{
"status": "affected",
"version": "3727b4968453dbab8fe18f979d67285eb6b66801",
"lessThan": "55126ef66298e43c69f192acebae8c7cc0022cf6",
"versionType": "git"
},
{
"status": "affected",
"version": "3727b4968453dbab8fe18f979d67285eb6b66801",
"lessThan": "14511c9b54ceeeef487409d73947c89ee8563590",
"versionType": "git"
}
],
"programFiles": [
"sound/soc/soc-dapm.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "3.15"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "3.15",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"sound/soc/soc-dapm.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:16:55.697",
"references": [
{
"url": "https://git.kernel.org/stable/c/10a36512c21f861a03fba461a7ead09023df9c1b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/14511c9b54ceeeef487409d73947c89ee8563590",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/32fc048391112559c34cb88d13594546939a4cd6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/496081b4edc1f6e662418831c5b14cddd8d7920c",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/55126ef66298e43c69f192acebae8c7cc0022cf6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/57ab955bde747327fb2042516ae1b7192c30e881",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/806fa4e1f2bf73c54bc4b6360790ecc69d095ca5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/faf539af1a595a26e5a081a4e512caee2bc2f4c5",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: dapm: Fix off-by-one check on the second enum channel\n\nThe snd_soc_dapm_put_enum_double() rejects item[0] once it reaches\ne->items, but it lets item[1] be equal to it. Both go on to\nsnd_soc_enum_item_to_val(), which indexes e->values with no bound of\nits own, so an enum with a value table reads one element past the end.\n\nThe indexing arrived with the MUX consolidation, which relaxed the\nitem[1] check in the same hunk. The value MUX handler it deleted used\n>= there, and the snd_soc_put_enum_double() in soc-ops.c still does.\n\nOnly adav80x pairs a value table with two shifts, and its second\nchannel looks accidental, but the control does report two values.\nWriting three into it reads off the end of adav80x_mux_values. The\ncore catches that only under CONFIG_SND_CTL_INPUT_VALIDATION, which\ndefaults off."
}
],
"lastModified": "2026-09-17T17:16:55.697",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}