SB2026090527 - Type Confusion in Linux kernel soc codecs
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Type Confusion (CVE-ID: CVE-2026-80910)
CWE-ID: CWE-843 - Type confusion
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access of an enumerated control value through an integer union member in the lpass-wsa-macro codec driver when reading affected enumerated controls. A local user can read an affected control to cause a denial of service.
The issue occurs on 64-bit kernels with CONFIG_SND_CTL_DEBUG enabled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/2fe7a89b2b5b73be35c1e493d0246314ba54e427
- https://git.kernel.org/stable/c/4bcac4bf304a3ec746192e49a669c236aaf27dbf
- https://git.kernel.org/stable/c/524aa7b9954b0a43dd13f71ecbbac52a151c326d
- https://git.kernel.org/stable/c/56f24311fd5607588a47e44675195a9efb200f29
- https://git.kernel.org/stable/c/7bcdde412e6c744f6135e02b12a735e2e37b639f
- https://git.kernel.org/stable/c/891129df5de79cd533ae335c6eab24df2ff2b0fd
- https://git.kernel.org/stable/c/bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d