Executive brief
A vulnerability was identified in the Linux kernel's audio multiplexer driver (simple-mux). This component is responsible for routing audio signals between different hardware paths. An error in how the system validates user input could allow an invalid configuration to be set, potentially leading to unpredictable system behavior or memory access issues within the audio subsystem.
Technical details
An off-by-one error exists in the simple_mux_control_put() function within sound/soc/codecs/simple-mux.c. The driver incorrectly used a '>' comparison instead of '>=' when validating enum control items against e->items. Because enum values are zero-based, this allowed a value equal to e->items to be accepted as valid. This invalid state is subsequently passed to the GPIO setter and the DAPM mux update path, where it is used as an index into the enum text array, potentially leading to an out-of-bounds read or undefined behavior. The issue has been patched across multiple stable kernel branches.
Affected products
- Linux Linux 5.11 to 5.15.210, 6.1.176, 6.6.143, 6.12.93
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://git.kernel.org/stable/c/05ef77f02607a3dc5d7f9762cb990f76843315d4
- https://git.kernel.org/stable/c/164dcbec9632ca93ae313e6da6e4e05584fa0f02
- https://git.kernel.org/stable/c/2ff3ac6f7664fe5639cad01712ac5e021fa7939c
- https://git.kernel.org/stable/c/5fe860af8630cf7c78523cbd68e5a234743585aa
- https://git.kernel.org/stable/c/6fb653b62f169f6050fac45b56bf21ad097e19f6
- https://git.kernel.org/stable/c/d8cc3e747b002a8b965c529de79c0654675b9a1a
- https://git.kernel.org/stable/c/f63ad68e18d774a5d15cd7e405ead63f6b322679