Linux Kernel Vulnerability in ASoC Codecs Affecting Audio Controls
CVE-2026-80583
What is CVE-2026-80583?
A vulnerability in the Linux kernel's ASoC (ALSA System on Chip) codecs was discovered, where the controls for DEC0 MODE to DEC7 MODE incorrectly accessed their values, leading to potential out-of-bounds memory accesses. This flaw originated from using the wrong data type for accessing enumerated items, which can cause erratic behavior in audio controls. A fix was introduced in sibling drivers but was overlooked in the tx-macro driver, resulting in read failures when the sound control entries exceeded their intended limits. The issue manifests itself in 64-bit kernel configurations with CONFIG_SND_CTL_DEBUG enabled, triggering a failure response (-EINVAL) when access violations are detected.
Affected Version(s)
Linux c39667ddcfc516fee084e449179d54430a558298 < 3ee3c26ceee562079596abc9bc3307dd56dab4ed
Linux c39667ddcfc516fee084e449179d54430a558298 < 1ba381759e45d5d0442452cfa5c42e836191a568
Linux 5.12