CVE-2026-72301

Source
https://cve.org/CVERecord?id=CVE-2026-72301
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72301.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72301
Downstream
Published
2026-08-15T05:55:20Z
Modified
2026-08-18T03:56:40Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get

In sof_ipc3_bytes_put(), the size used for the memcpy is derived from the old data->size already in the buffer, not the incoming new data's size field. If the new data has a different size, the copy length is wrong: it may truncate valid data or copy stale bytes.

Similarly, sof_ipc3_bytes_get() checks data->size against max_size without accounting for the sizeof(struct sof_ipc_ctrl_data) offset of the flex array within the allocation.

Fix bytes_put to validate and use the incoming data's sof_abi_hdr.size from ucontrol before copying. Fix bytes_get to subtract sizeof(*cdata) from the bounds check to match the actual available space.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72301.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
544ac8858f249950b4d99c68e538cdc07300528f
Fixed
8bd715a9d882fe1993bb2aec5eff89fffa946592
Fixed
0dce240145f47545d2e4b18c6d58033b83e1fd0e
Fixed
ed4f758f34be4c32e02933ac4fa044589d9c1c16
Fixed
0c4fbdaca225b97122b61b68c5353caa33a253c3
Fixed
92f90917413bdd6078fefff6f6c83a07bf870b04
Fixed
1f97760417b5faa60e9642fd0ed61eb17d0b1b39

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72301.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72301.json"