Executive brief
The Linux kernel's audio subsystem (ASoC) contains a flaw in topology configuration parsing that fails to validate name string boundaries before use. An attacker with the ability to supply a malformed audio topology configuration file could cause the kernel to read past fixed-size memory boundaries, potentially leading to information disclosure or denial of service.
Technical details
The vulnerability is a buffer over-read (CWE-125) in the ASoC topology parser (sound/soc/soc-topology.c). The parser processes PCM and DAI name fields stored in fixed-size UAPI arrays without validating that they are properly NUL-terminated before passing them to strlen(), devm_kstrdup(), DAI lookup functions, and diagnostic print routines. A malformed topology blob with unterminated name fields can cause the kernel to read past the end of fixed-size buffer boundaries. The attack requires local ability to supply a crafted audio topology configuration file. The fix adds a bounded strnlen() check (soc_tplg_check_name) before consuming these fields as C strings, rejecting any field that reaches the maximum length without termination.
Affected products
- Linux Linux kernel Affected by topology code in sound subsystem; patched in various stable branches
Timeline
- 2026-08-15: disclosed
- 2026-06-04: patched: Upstream commit b7e44d1986d6671342c19b82192189ca5db5dab7