CVE-2026-98263

Source
https://cve.org/CVERecord?id=CVE-2026-98263
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98263.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98263
Downstream
Published
2026-10-06T08:45:26Z
Modified
2026-10-08T02:52:56Z
Summary
ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type
Details

In the Linux kernel, the following vulnerability has been resolved:

ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type

stream_config is not initialized before being passed to sdw_stream_add_slave(). The type field may contain garbage and is later copied to stream->type by sdw_config_stream().

Zero-initialize stream_config so type defaults to SDW_STREAM_PCM.

While at it, use snd_sdw_params_to_config() helper instead of open-coding the same logic.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98263.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
63a511284c9ea72696a5dd0a2d2721bdef19f774
Fixed
6507055733a9d397289277408b52daf422f8a814
Fixed
c144447c207e2be24d6ac86d544691ba464caad8
Fixed
d93988c9e58d37b677f6ee8aceae741c8d1e30ad
Fixed
a318ee718e7448cd6bf62d9b3197b6a6a8d4701e
Fixed
03a5699a0a04309c597683967aaaf25d1e555ea2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98263.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.4.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98263.json"