CVE-2026-72261
ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocation size. If local_cdata->data->size was previously set to an inconsistent value, the memcpy could write past the allocated buffer. Add a bounds check to ensure num_elems fits within the available space in the ipc_control_data allocation before copying.
INFO
Published Date :
Aug. 15, 2026, 6:21 a.m.
Last Modified :
Aug. 17, 2026, 6:18 a.m.
Remotely Exploit :
No
Source :
416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS 3.1 | HIGH | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
Solution
- Update the Linux kernel to include the fix.
- Validate firmware control data sizes.
- Ensure memcpy operations stay within allocated buffer bounds.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-72261.
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-72261 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-72261
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-72261 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-72261 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 17, 2026
Action Type Old Value New Value Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Changed Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '1dc25a3e06364f48c4ef06016852f8b82425151a', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'ee781058cd4d71e4449f41cbe6a3b8c59daa2c51', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'ecf67f1302f2080b4d241b973364aacda70ad740', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'd3abaedf6a58469610136d2dace1a85cddf7afcf', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '2a591bf6fd41fd14bdae689aafac4a9ee702c23c', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '390aa4c9339bb0ec0bc8d554e830faf93ca9d49e', 'versionType': 'git'}], 'programFiles': ['sound/soc/sof/ipc3-control.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.18'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.18', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['sound/soc/sof/ipc3-control.c'], 'defaultStatus': 'affected'}] [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '1dc25a3e06364f48c4ef06016852f8b82425151a', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'ee781058cd4d71e4449f41cbe6a3b8c59daa2c51', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'ecf67f1302f2080b4d241b973364aacda70ad740', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'd3abaedf6a58469610136d2dace1a85cddf7afcf', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '2a591bf6fd41fd14bdae689aafac4a9ee702c23c', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '390aa4c9339bb0ec0bc8d554e830faf93ca9d49e', 'versionType': 'git'}], 'programFiles': ['sound/soc/sof/ipc3-control.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.18'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.18', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['sound/soc/sof/ipc3-control.c'], 'defaultStatus': 'affected'}] -
New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Aug. 15, 2026
Action Type Old Value New Value Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '1dc25a3e06364f48c4ef06016852f8b82425151a', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'ee781058cd4d71e4449f41cbe6a3b8c59daa2c51', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'ecf67f1302f2080b4d241b973364aacda70ad740', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': 'd3abaedf6a58469610136d2dace1a85cddf7afcf', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '2a591bf6fd41fd14bdae689aafac4a9ee702c23c', 'versionType': 'git'}, {'status': 'affected', 'version': '10f461d79c2d1afb22344986cc1b4631169cf25e', 'lessThan': '390aa4c9339bb0ec0bc8d554e830faf93ca9d49e', 'versionType': 'git'}], 'programFiles': ['sound/soc/sof/ipc3-control.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '5.18'}, {'status': 'unaffected', 'version': '0', 'lessThan': '5.18', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '6.1.178', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.145', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.97', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.40', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.1.5', 'versionType': 'semver', 'lessThanOrEqual': '7.1.*'}, {'status': 'unaffected', 'version': '7.2-rc1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['sound/soc/sof/ipc3-control.c'], 'defaultStatus': 'affected'}] Added Description In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocation size. If local_cdata->data->size was previously set to an inconsistent value, the memcpy could write past the allocated buffer. Add a bounds check to ensure num_elems fits within the available space in the ipc_control_data allocation before copying. Added Reference https://git.kernel.org/stable/c/1dc25a3e06364f48c4ef06016852f8b82425151a Added Reference https://git.kernel.org/stable/c/2a591bf6fd41fd14bdae689aafac4a9ee702c23c Added Reference https://git.kernel.org/stable/c/390aa4c9339bb0ec0bc8d554e830faf93ca9d49e Added Reference https://git.kernel.org/stable/c/d3abaedf6a58469610136d2dace1a85cddf7afcf Added Reference https://git.kernel.org/stable/c/ecf67f1302f2080b4d241b973364aacda70ad740 Added Reference https://git.kernel.org/stable/c/ee781058cd4d71e4449f41cbe6a3b8c59daa2c51