Linux Kernel Vulnerability in ASoC Codecs Affecting Audio Controls
CVE-2026-80583

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80583?

A vulnerability in the Linux kernel's ASoC (ALSA System on Chip) codecs was discovered, where the controls for DEC0 MODE to DEC7 MODE incorrectly accessed their values, leading to potential out-of-bounds memory accesses. This flaw originated from using the wrong data type for accessing enumerated items, which can cause erratic behavior in audio controls. A fix was introduced in sibling drivers but was overlooked in the tx-macro driver, resulting in read failures when the sound control entries exceeded their intended limits. The issue manifests itself in 64-bit kernel configurations with CONFIG_SND_CTL_DEBUG enabled, triggering a failure response (-EINVAL) when access violations are detected.

Affected Version(s)

Linux c39667ddcfc516fee084e449179d54430a558298 < 3ee3c26ceee562079596abc9bc3307dd56dab4ed

Linux c39667ddcfc516fee084e449179d54430a558298 < 1ba381759e45d5d0442452cfa5c42e836191a568

Linux 5.12

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.