CVE-2026-74293 (GCVE-0-2026-74293)
Vulnerability from cvelistv5
Published
2026-08-15 05:57
Modified
2026-08-17 05:45
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
ASoC: fsl: fsl_audmix: Validate written enum values
fsl_audmix_put_mix_clk_src() and fsl_audmix_put_out_src()
convert the user-provided enum item with snd_soc_enum_item_to_val()
before checking whether the item is within the enum's item count.
The generic snd_soc_put_enum_double() helper performs that
validation, but these callbacks use the converted value first: the
clock-source path tests it with BIT(), and the output-source path
indexes the prms transition table with it.
Reject out-of-range enum items before converting them.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: be1df61cf06efb355c90702e46b8d46f055acb4e Version: be1df61cf06efb355c90702e46b8d46f055acb4e Version: be1df61cf06efb355c90702e46b8d46f055acb4e Version: be1df61cf06efb355c90702e46b8d46f055acb4e Version: be1df61cf06efb355c90702e46b8d46f055acb4e Version: be1df61cf06efb355c90702e46b8d46f055acb4e Version: be1df61cf06efb355c90702e46b8d46f055acb4e Version: be1df61cf06efb355c90702e46b8d46f055acb4e |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/fsl/fsl_audmix.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "7513831b90a38d55fa089e3e1b49691e467afee6",
"status": "affected",
"version": "be1df61cf06efb355c90702e46b8d46f055acb4e",
"versionType": "git"
},
{
"lessThan": "b4774a7da12b14fc37219ab4368d1907f9b5aca4",
"status": "affected",
"version": "be1df61cf06efb355c90702e46b8d46f055acb4e",
"versionType": "git"
},
{
"lessThan": "8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3",
"status": "affected",
"version": "be1df61cf06efb355c90702e46b8d46f055acb4e",
"versionType": "git"
},
{
"lessThan": "0b10c6203e62d9e7337cc401568b201f9bac79ec",
"status": "affected",
"version": "be1df61cf06efb355c90702e46b8d46f055acb4e",
"versionType": "git"
},
{
"lessThan": "b36d6d48faa6b1bb723b8f4e527c531a1a68520e",
"status": "affected",
"version": "be1df61cf06efb355c90702e46b8d46f055acb4e",
"versionType": "git"
},
{
"lessThan": "0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c",
"status": "affected",
"version": "be1df61cf06efb355c90702e46b8d46f055acb4e",
"versionType": "git"
},
{
"lessThan": "5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a",
"status": "affected",
"version": "be1df61cf06efb355c90702e46b8d46f055acb4e",
"versionType": "git"
},
{
"lessThan": "3cd17e4e2871114d5579fa7bc8da66faf7fc1930",
"status": "affected",
"version": "be1df61cf06efb355c90702e46b8d46f055acb4e",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/fsl/fsl_audmix.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.2"
},
{
"lessThan": "5.2",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.97",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.40",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.5",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.97",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.40",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.5",
"versionStartIncluding": "5.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "5.2",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_audmix: Validate written enum values\n\nfsl_audmix_put_mix_clk_src() and fsl_audmix_put_out_src()\nconvert the user-provided enum item with snd_soc_enum_item_to_val()\nbefore checking whether the item is within the enum\u0027s item count.\n\nThe generic snd_soc_put_enum_double() helper performs that\nvalidation, but these callbacks use the converted value first: the\nclock-source path tests it with BIT(), and the output-source path\nindexes the prms transition table with it.\n\nReject out-of-range enum items before converting them."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.8,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:L - Exploitation requires a local SNDRV_CTL_IOCTL_ELEM_WRITE to /dev/snd/controlC* for the fsl-audmix \"Output Source\" or \"Mixing Clock Source\" mixer controls; no network, Bluetooth, or physical-input path reaches these put callbacks.\nAC:L - On default builds without CONFIG_SND_CTL_INPUT_VALIDATION, a single ioctl supplying an out-of-range enumerated.item[0] deterministically reaches the buggy snd_soc_enum_item_to_val()/prms[] indexing before snd_soc_put_enum_double() rejects the value; no race or uncontrollable state is needed.\nPR:L - snd_ctl_open() and snd_ctl_elem_write() perform no capability or namespace checks; any local user with ordinary access to the ALSA control device (common on i.MX8QM/i.MX952 automotive/embedded systems via audio-group or seat ACLs) can trigger the vulnerable callbacks.\nUI:N - The attacker issues the control write from its own process after opening the control device; no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - The flaw corrupts or misreads kernel data and programs on-chip AUDMIX MMIO within the same host kernel security authority; it does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Out-of-range enum indices are used to index the static prms[out_src][val] transition table and in BIT(val) before bounds checks, causing out-of-bounds reads of kernel rodata that are copied into transition state and can disclose adjacent memory contents.\nI:H - Attacker-chosen indices can select unintended prms transition cells or out-of-bounds prm data that pass fsl_audmix_state_trans() and drive snd_soc_component_update_bits() to write attacker-influenced mask/ctr values into AUDMIX hardware control registers.\nA:H - Large enum values can provoke undefined BIT() shifts, read past the prms table boundary, and program invalid AUDMIX control-register states that can kernel-fault or hang the audio subsystem; conservative scoring treats this memory-corruption class as high availability impact."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T05:45:31.193Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/7513831b90a38d55fa089e3e1b49691e467afee6"
},
{
"url": "https://git.kernel.org/stable/c/b4774a7da12b14fc37219ab4368d1907f9b5aca4"
},
{
"url": "https://git.kernel.org/stable/c/8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3"
},
{
"url": "https://git.kernel.org/stable/c/0b10c6203e62d9e7337cc401568b201f9bac79ec"
},
{
"url": "https://git.kernel.org/stable/c/b36d6d48faa6b1bb723b8f4e527c531a1a68520e"
},
{
"url": "https://git.kernel.org/stable/c/0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c"
},
{
"url": "https://git.kernel.org/stable/c/5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a"
},
{
"url": "https://git.kernel.org/stable/c/3cd17e4e2871114d5579fa7bc8da66faf7fc1930"
}
],
"title": "ASoC: fsl: fsl_audmix: Validate written enum values",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-74293",
"datePublished": "2026-08-15T05:57:58.889Z",
"dateReserved": "2026-08-15T05:44:03.881Z",
"dateUpdated": "2026-08-17T05:45:31.193Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…