Type Confusion in Linux kernel - CVE-2026-80910
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper access of an enumerated control value through an integer union member in the lpass-wsa-macro codec driver when reading affected enumerated controls. A local user can read an affected control to cause a denial of service.
The issue occurs on 64-bit kernels with CONFIG_SND_CTL_DEBUG enabled.
Affected software
How to mitigate CVE-2026-80910
External References
- https://git.kernel.org/stable/c/2fe7a89b2b5b73be35c1e493d0246314ba54e427
- https://git.kernel.org/stable/c/4bcac4bf304a3ec746192e49a669c236aaf27dbf
- https://git.kernel.org/stable/c/524aa7b9954b0a43dd13f71ecbbac52a151c326d
- https://git.kernel.org/stable/c/56f24311fd5607588a47e44675195a9efb200f29
- https://git.kernel.org/stable/c/7bcdde412e6c744f6135e02b12a735e2e37b639f
- https://git.kernel.org/stable/c/891129df5de79cd533ae335c6eab24df2ff2b0fd
- https://git.kernel.org/stable/c/bd4e5f9c3b764dc0e2a5662f92d63d2f3767a78d