Executive brief
The Linux kernel's Tegra audio subsystem driver contains an out-of-bounds read vulnerability in its enumeration value handler. An attacker with local access to audio control settings could read memory beyond array bounds, potentially exposing sensitive kernel data or causing a system crash. This affects audio routing on Tegra-based systems including NVIDIA Jetson and some mobile devices.
Technical details
The vulnerability is a bounds-check-bypass (CWE-367) in the tegra_ahub_put_value_enum() function within sound/soc/tegra/tegra210_ahub.c. The function reads from e->values[item[0]] before validating that item[0] is within the valid enum range (item[0] < e->items). An attacker can supply an out-of-range enum index via snd_kcontrol to trigger an out-of-bounds read of the values array. The fix moves the bounds check before the array access. Local user interaction is required (access to audio mixer controls), and the attack surface is limited to systems with Tegra audio hardware. A patch was committed on 2026-06-11 and backported to stable kernels.
Affected products
- Linux Linux kernel Multiple versions prior to fix commit 1d8aabb413b5638670dfd1162169edc0ba276a2e (2026-06-11)
Timeline
- 2026-08-15: disclosed
- 2026-06-11: patched