Audio Vulnerability in Linux Kernel Affecting Greybus Topology Parsing
CVE-2026-93280
What is CVE-2026-93280?
A vulnerability in the Linux kernel's Greybus audio module allows for improper validation of topology blob sizes during data parsing. This issue arises when the gb_audio_gb_get_topology() function fetches a topology blob based on a module-supplied size, which is not adequately checked against the actual fetched blob size. As a result, a module can report a smaller topology size but larger section sizes, leading to offsets that exceed the allocated memory. If not addressed, this can allow attackers to read beyond memory bounds, potentially leading to information leakage or system instability. It is crucial to validate section sizes against the fetched blob size to mitigate this risk effectively.
Affected Version(s)
Linux 184992e305f1de3a3d5fa446da3a2bc76be7c54a
Linux 184992e305f1de3a3d5fa446da3a2bc76be7c54a
Linux 184992e305f1de3a3d5fa446da3a2bc76be7c54a < 6f764363b3173d805be11e59a8f23ecee2d420d5