SB20260816116 - Heap-based buffer overflow in Linux kernel soc sof
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Heap-based buffer overflow (CVE-ID: CVE-2026-72262)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service or disclose sensitive information.
The vulnerability exists due to a heap-based buffer overflow and out-of-bounds read in the SOF IPC3 bytes control handling in sound/soc/sof/ipc3-control.c when processing data through the ALSA TLV kcontrol interface. A local user can send specially crafted control data to cause a denial of service or disclose sensitive information.
The issue affects the bytes_ext put and get paths, including an error-path restore operation that can write past the end of the allocated buffer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/121577383b5cf221e86581e0f2bcca4c66f17469
- https://git.kernel.org/stable/c/1adde1941bba7b0d7104b86ed819d48d81cb0ad9
- https://git.kernel.org/stable/c/eaa67e139c9217099e2a7b717aeeb46c65de3494
- https://git.kernel.org/stable/c/f4933e1d11b97b6a0951648b7c3e53850e1b33a9
- https://git.kernel.org/stable/c/fd46668d538993218eea19c6925c868ac0f2630c