CVE-2026-74293

Source
https://cve.org/CVERecord?id=CVE-2026-74293
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74293.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74293
Downstream
Published
2026-08-15T05:57:58.889Z
Modified
2026-08-18T03:56:56.667274902Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ASoC: fsl: fsl_audmix: Validate written enum values
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: fsl: fsl_audmix: Validate written enum values

fslaudmixputmixclksrc() and fslaudmixputoutsrc() convert the user-provided enum item with sndsocenumitemtoval() before checking whether the item is within the enum's item count.

The generic sndsocputenumdouble() helper performs that validation, but these callbacks use the converted value first: the clock-source path tests it with BIT(), and the output-source path indexes the prms transition table with it.

Reject out-of-range enum items before converting them.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74293.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
be1df61cf06efb355c90702e46b8d46f055acb4e
Fixed
7513831b90a38d55fa089e3e1b49691e467afee6
Fixed
b4774a7da12b14fc37219ab4368d1907f9b5aca4
Fixed
8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3
Fixed
0b10c6203e62d9e7337cc401568b201f9bac79ec
Fixed
b36d6d48faa6b1bb723b8f4e527c531a1a68520e
Fixed
0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c
Fixed
5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a
Fixed
3cd17e4e2871114d5579fa7bc8da66faf7fc1930

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74293.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.2.0
Fixed
5.10.261
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74293.json"