CVE-2026-74295

Source
https://cve.org/CVERecord?id=CVE-2026-74295
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74295.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74295
Downstream
Published
2026-08-15T05:58:00.123Z
Modified
2026-08-18T03:56:45.862681239Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
ASoC: codecs: hdac_hdmi: Validate written enum value
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: codecs: hdac_hdmi: Validate written enum value

hdachdmisetpinportmux() uses the written enum value to index the texts array before calling sndsocdapmputenumdouble(), which validates that the value is within the enum item range.

An out-of-range value can therefore make the driver read past the texts array before the helper rejects the write. Move the lookup after the helper has accepted the value.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74295.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
4a3478debf36c0aa0cf0860daec245b13cd4448f
Fixed
216336418c007c4b44c650acf2fd3d2de5bb81e8
Fixed
bc464a6a9e352daa17b1636c090cf3185710b9a0
Fixed
8cbf24714d6b3f553fc959632c9781176a73a9a7
Fixed
7f02e9064b6f84e7f93c72f134306271eb4f7de4
Fixed
9131e4b023e0db5764680034bdc94aeae0b0f33d
Fixed
d8961b5c7889b6ecc00f1409d36826df1665df27
Fixed
0b08baeccdcf52fad328ad645f5b4fbee04eea34

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74295.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
5.15.212
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.178
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.145
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74295.json"