Junglewise Threat Intelligence

CVE-2026-46179: Linux Kernel division by zero in ASoC SOF compressed streams

CVE-2026-46179 · Severity: info · CVSS 0 · Published 2026-05-28

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability exists in the Linux kernel's audio subsystem (ASoC SOF) that could allow a local user to cause a system crash. The issue occurs when the system attempts to process audio data for a stream that has not been properly configured, leading to a mathematical error (division by zero). This could result in a denial-of-service, impacting the stability of devices using affected Linux kernels.

Technical details

A division-by-zero vulnerability exists in 'sound/soc/sof/compress.c' within the Linux kernel's ASoC SOF component. The 'sof_compr_pointer' function calculates the I/O frame position by dividing the current position by the product of the number of channels and container bytes. Because these values default to zero and are only initialized during stream parameter configuration, an attacker or malformed application can trigger a kernel panic by performing pointer operations on an unconfigured stream. The fix introduces validation to ensure 'sstream->channels' and 'sstream->sample_container_bytes' are non-zero before performing the division, returning -EBUSY otherwise. Patches have been released across multiple stable kernel branches.

Affected products

  • Linux Linux Kernel Versions prior to the May 2026 patches (including various stable branches)

Timeline

  • 2026-03-26: other: Patch authored by Mark Brown
  • 2026-05-28: advisory: CVE-2026-46179 published by NVD
  • 2026-05-14: patched: Patches committed to various stable kernel trees

References