CVE-2026-72302

Source
https://cve.org/CVERecord?id=CVE-2026-72302
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72302.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-72302
Downstream
Published
2026-08-15T05:55:21.049Z
Modified
2026-08-16T03:48:53.833895883Z
Summary
ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc

In sofipc3controlupdate(), the expectedsize calculation uses firmware-provided cdata->numelems in arithmetic that could overflow on 32-bit platforms, wrapping to a small value. This would allow the cdata->rhdr.hdr.size comparison to pass with mismatched sizes, potentially leading to out-of-bounds access in sndsofupdatecontrol.

Use checkmuloverflow() and checkaddoverflow() to detect and reject overflowed size calculations.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72302.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
10f461d79c2d1afb22344986cc1b4631169cf25e
Fixed
6856b3c23b0995eefad5a6142b4365ef70e1fe4a
Fixed
89a2309a9eec80d4c19e3aed62c4f923594d1911
Fixed
ffd79e77f2fbacd7a5d40ad1d4c7f3f089a8f2f3
Fixed
711d912b18763af62a63aa8f2419a774eb63bba4
Fixed
312c7d2ebe696da3f885eee77d52297664e57c53
Fixed
8791977d7289f6e9d2b014f60a5455f053a7bc04

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72302.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.18.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72302.json"