SB2026081668 - Improper input validation in Linux kernel soc sof
Published: August 16, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper input validation (CVE-ID: CVE-2026-72304)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in sof_ipc4_bytes_put when processing user-supplied control data. A local user can provide crafted control data with a mismatched size field to cause a denial of service.
The copy length is derived from the previously stored buffer header rather than the incoming header, which can result in truncated data or stale bytes being copied.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/038406abde0d0883419ec89425ea941ec8bbef95
- https://git.kernel.org/stable/c/266f936db83aee6ca6473bbb06259bda52bf4fc3
- https://git.kernel.org/stable/c/3ad673e7139cf214afd24321a829aad6575f4163
- https://git.kernel.org/stable/c/4cf6a7ebbf8787393b158b2cc341723e5bebc4a8
- https://git.kernel.org/stable/c/fb4293173db2d474d8fbc0e5ecf4943e6df2b40e