Executive brief
A vulnerability in the Linux kernel's audio driver for Texas Instruments TAS2781 amplifiers could lead to system instability. The issue occurs when the system attempts to manage audio calibration data, potentially causing memory corruption. In practice, this could allow a local user to crash the system or potentially gain unauthorized access to sensitive information.
Technical details
A vulnerability exists in the Linux kernel's ALSA (Advanced Linux Sound Architecture) subsystem within the tas2781_hda_i2c.c driver. During a code refactoring to unify calibration data management, a reference to 'tasdevice_priv' was incorrectly assigned to 'h->hda_priv' instead of 'h->priv'. Because the variable is a void pointer, the compiler failed to detect the type mismatch, leading to memory corruption when the pointer is dereferenced. A local attacker with low privileges could exploit this to cause a kernel panic (DoS) or potentially achieve arbitrary code execution. The issue has been patched in kernel version 6.16.4 and later.
Affected products
- Linux Linux Kernel 6.16 to 6.16.4
Timeline
- 2025-08-20: patched: Initial patch submitted by Takashi Iwai
- 2025-09-05: disclosed: CVE published by kernel.org