SB2026081668 - Improper input validation in Linux kernel soc sof



SB2026081668 - Improper input validation in Linux kernel soc sof

Published: August 16, 2026

Security Bulletin ID SB2026081668
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper input validation (CVE-ID: CVE-2026-72304)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in sof_ipc4_bytes_put when processing user-supplied control data. A local user can provide crafted control data with a mismatched size field to cause a denial of service.

The copy length is derived from the previously stored buffer header rather than the incoming header, which can result in truncated data or stale bytes being copied.


Remediation

Install update from vendor's website.