Linux Kernel Vulnerability: ASoC SDCA Message Size Check Flaw
CVE-2026-80900

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-80900?

A vulnerability in the Linux kernel's ASoC (ALSA System on Chip) SDCA (Smart Device Control Architecture) allows for improper validation of message sizes. This can lead to scenarios where the message offset exceeds the buffer length, enabling size checks to incorrectly validate, potentially causing system instability or exploitation. A refactor of the size checking mechanism has been implemented to enhance its robustness against invalid size inputs, thereby strengthening the overall security of the Linux kernel.

Affected Version(s)

Linux daab108504be73182c16a72b9cfe47ac3b1928ca

Linux daab108504be73182c16a72b9cfe47ac3b1928ca < 556d872e7c2a0b570c5b0974813847ef0d0cd637

Linux 6.19

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.