CVE-2026-93280

Source
https://cve.org/CVERecord?id=CVE-2026-93280
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93280.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93280
Downstream
Published
2026-09-24T15:52:22Z
Modified
2026-09-25T03:48:54Z
Summary
greybus: audio: bound the topology section sizes against the fetched size
Details

In the Linux kernel, the following vulnerability has been resolved:

greybus: audio: bound the topology section sizes against the fetched size

gb_audio_gb_get_topology() fetches a topology blob of a module-supplied size, and gbaudio_tplg_parse_data() then walks it by adding the module-supplied size_dais, size_controls and size_widgets fields to form the control, widget and route section offsets. Those le32 sizes are never checked against the fetched blob, so a module reporting a small topology size but large section sizes makes the offsets point past the allocation, and parsing reads out of bounds.

Reject a topology whose section sizes do not fit within the fetched size before it is parsed.

Database specific
{
    "cna_assigner":  "Linux",
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93280.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
184992e305f1de3a3d5fa446da3a2bc76be7c54a
Fixed
ba86de9f7b0d7903d2df5ea2373e34d8ca3fc43e
Fixed
dd5593aee0a0fb353e1164aff7b65e563fe1f232
Fixed
6f764363b3173d805be11e59a8f23ecee2d420d5
Fixed
52daf9de692ebac813d110eb1e677dc0e1f4a5ab
Fixed
d0f6eaba60705bacd9bb4ce48eab50ef3f546777
Fixed
c9191f2e2f35f1209eb2dc24b31129dd47b48c16
Fixed
cfcc5a41a9664eb68023aae4cd0d485b256bd7c7
Fixed
33d8c7b794d2a30637c9d3fcb478f1d3222bef1e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93280.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.9.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93280.json"