In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc4-topology: Refresh copier IPC payload before widget setup
The ipcconfigdata buffer for copier widgets is built once during ipcprepare (called from sofpcmsetupconnectedwidgets) and cached for reuse. For host copiers this buffer contains the copierdata with gtwcfg.nodeid (host DMA ID). For DAI copiers it additionally includes a dmaconfigtlv trailer with streamid and dmachannel_id for HDA link DMA.
On suspend/resume, both host and link DMA streams are released and re-allocated with potentially different stream tags. The underlying copierdata and dmaconfigtlv structures are correctly updated by hostconfig and sdwhdadaihwparams respectively. However, since the widget list (spcm->stream[].list) persists across suspend, sofpcmhwparams skips sofpcmsetupconnectedwidgets and ipcprepare never runs again to rebuild ipcconfigdata. The stale cached payload is then sent to firmware with boot-time DMA channel assignments, causing DMA channel conflicts that lead to firmware errors and crashes.
Fix this by refreshing copierdata and dmaconfigtlv portions of ipcconfigdata in sofipc4widgetsetup right before the IPC message is sent. This ensures the payload always reflects the current DMA state regardless of whether ipc_prepare ran.
For DAI copiers, the gtwcfg.configlength in copierdata is temporarily inflated to include the TLV size (matching the ipcconfigdata layout) before copying, then restored, mirroring what sofipc4preparecopier_module does when first building the buffer.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80525.json"
}