Executive brief
The Linux kernel's audio codec control interface (ASoC SDCA) contains a buffer over-read vulnerability in enum value validation. A local attacker with the ability to write to audio control parameters can read past the end of an allocated memory buffer, potentially exposing sensitive kernel data or triggering a denial of service. This affects systems using SDCA-compatible audio hardware.
Technical details
The vulnerability is a heap buffer over-read in the ge_put_enum_double() function in sound/soc/sdca/sdca_asoc.c. The function accepts a user-supplied enumeration index in item[0] and passes it directly to snd_soc_enum_item_to_val() without validating it against the number of valid enum items. When snd_soc_enum_item_to_val() indexes the e->values[] heap-allocated array with an out-of-bounds index, it reads beyond the buffer boundaries. The fix adds a bounds check (if item[0] >= e->items) before the vulnerable call to reject invalid indices. Attack preconditions include local access and the ability to write to audio control nodes. The patch was released in June 2026 and backported to stable kernel branches.
Affected products
- Linux Linux kernel affected versions include 5.x, 6.x, and 7.x series (fix backported across stable branches)
Timeline
- 2026-08-15: disclosed: CVE published on NVD
- 2026-06-23: patched: Original fix committed to mainline
- 2026-07-24: patched: Backported to stable kernels via Sasha Levin