Junglewise Threat Intelligence

CVE-2026-64041: Linux Kernel buffer overflow in fs210x audio codec driver

CVE-2026-64041 · Severity: info · CVSS 0 · Published 2026-07-19

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's audio amplifier driver for FourSemi FS2104/5S devices. This flaw could allow a local attacker to cause a buffer overflow, potentially leading to system instability or unauthorized memory access. The issue has been resolved in recent kernel updates.

Technical details

A buffer overflow vulnerability exists in the fs210x audio codec driver within the Linux kernel, specifically in the fs210x_effect_scene_info() function in sound/soc/codecs/fs210x.c. The root cause is an incorrect use of the strscpy() function, where the length argument was derived from the source string's length (strlen(SRC) + 1) rather than the destination buffer's size. If the source string exceeds the destination buffer size, a heap-based buffer overflow occurs. This issue affects systems using FourSemi FS2104/5S audio amplifiers. Patches have been released in kernel versions 6.18.34, 7.0.11, and 7.1.

Affected products

  • Linux Linux Kernel 6.18 to 6.18.34, 7.0 to 7.0.11

Timeline

  • 2026-05-13: disclosed: Initial patch submitted by Alexander A. Klimov
  • 2026-07-19: advisory: CVE-2026-64041 published

References

Related threats