CVE-2026-80526

Source
https://cve.org/CVERecord?id=CVE-2026-80526
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80526.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80526
Downstream
Published
2026-08-26T14:37:05Z
Modified
2026-08-28T03:47:29Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ASoC: tas2562: Validate values for volume writes
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: tas2562: Validate values for volume writes

tas2562_volume_control_put() does not do any validation of the control value written by userspace, it uses it to look up a value in a fixed size array which can easily be overflowed and then writes whatever value it gets back to the device. Add validation that we are loading a value we have in the array.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80526.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
bf726b1c86f2caab70ad614cdf7da3b81ad08e69
Fixed
1f389ecd0c35e9e281036e44c121df904f3164c1
Fixed
20bdbb1376457ecbf418bf677fd285820d1fc011
Fixed
db488d653d896fcf9ac87e15239924c2928bbc3c
Fixed
c37a0461c0d0a70c5de4fdbd70449a7f53c12dda
Fixed
8fb41964f7e4e4207c8999af2056894caa7a252a

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80526.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.7.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80526.json"