CVE-2026-74332

Source
https://cve.org/CVERecord?id=CVE-2026-74332
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74332.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-74332
Downstream
Published
2026-08-15T05:58:25.112Z
Modified
2026-08-18T03:56:46.780219462Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ASoC: amd: acp-sdw-sof: Bound DAI link iteration
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: amd: acp-sdw-sof: Bound DAI link iteration

createsdwdailinks() walks sofdais until it finds an entry with initialised cleared, but sofdais is allocated with exactly num_ends entries. If all entries are initialised, the loop reads past the end of the array.

Pass the allocated entry count to createsdwdailinks() and stop before reading past the array.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74332.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
6d8348ddc56ed43ba39d1e8adda13299201f32ed
Fixed
0a5ff4000dd7a390139dd7823fef1de4963e490a
Fixed
9e82497138abea7d5c6e65015663d907fbcbf6b4
Fixed
86a64c049873fe4d4a6a378e27a333ab5631c4b2
Fixed
4d992e63f52d58f52b724606c60ae7b37a1c582f

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74332.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.12.0
Fixed
6.12.97
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.40
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-74332.json"