Out-of-bounds read in Linux kernel - CVE-2026-93280
Published: September 25, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to read out-of-bounds memory.
The vulnerability exists due to an out-of-bounds read in the Greybus audio topology parser when parsing a topology blob supplied by a connected module. An attacker with physical access can supply a topology blob with section sizes exceeding the fetched size to read out-of-bounds memory.
Affected software
How to mitigate CVE-2026-93280
External References
- https://git.kernel.org/stable/c/33d8c7b794d2a30637c9d3fcb478f1d3222bef1e
- https://git.kernel.org/stable/c/52daf9de692ebac813d110eb1e677dc0e1f4a5ab
- https://git.kernel.org/stable/c/6f764363b3173d805be11e59a8f23ecee2d420d5
- https://git.kernel.org/stable/c/ba86de9f7b0d7903d2df5ea2373e34d8ca3fc43e
- https://git.kernel.org/stable/c/c9191f2e2f35f1209eb2dc24b31129dd47b48c16
- https://git.kernel.org/stable/c/cfcc5a41a9664eb68023aae4cd0d485b256bd7c7
- https://git.kernel.org/stable/c/d0f6eaba60705bacd9bb4ce48eab50ef3f546777
- https://git.kernel.org/stable/c/dd5593aee0a0fb353e1164aff7b65e563fe1f232