Improper input validation in Linux kernel - CVE-2026-72304

 

Improper input validation in Linux kernel - CVE-2026-72304

Published: August 16, 2026


Vulnerability identifier: #VU143130
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72304
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in sof_ipc4_bytes_put when processing user-supplied control data. A local user can provide crafted control data with a mismatched size field to cause a denial of service.

The copy length is derived from the previously stored buffer header rather than the incoming header, which can result in truncated data or stale bytes being copied.


Affected software

Linux kernel

How to mitigate CVE-2026-72304

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins