CVE-2026-72261

HIGHCVSS 7.8/10EPSS 0.21%

Last modified

CVE-2026-72261 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocation size. If local_cdata->data->size was previously set to an inconsistent value, the memcpy could write past the allocated buffer. Add a bounds check to ensure num_elems fits within the available space in the ipc_control_data allocation before copying.. EPSS estimates a 0.21% chance of exploitation in the next 30 days.

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocation size. If local_cdata->data->size was previously set to an inconsistent value, the memcpy could write past the allocated buffer. Add a bounds check to ensure num_elems fits within the available space in the ipc_control_data allocation before copying.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.21%

10.9th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= 10f461d79c2d1afb22344986cc1b4631169cf25e, < 1dc25a3e06364f48c4ef06016852f8b82425151a; >= 10f461d79c2d1afb22344986cc1b4631169cf25e, < ee781058cd4d71e4449f41cbe6a3b8c59daa2c51; >= 10f461d79c2d1afb22344986cc1b4631169cf25e, < ecf67f1302f2080b4d241b973364aacda70ad740; >= 10f461d79c2d1afb22344986cc1b4631169cf25e, < d3abaedf6a58469610136d2dace1a85cddf7afcf; >= 10f461d79c2d1afb22344986cc1b4631169cf25e, < 2a591bf6fd41fd14bdae689aafac4a9ee702c23c; >= 10f461d79c2d1afb22344986cc1b4631169cf25e, < 390aa4c9339bb0ec0bc8d554e830faf93ca9d49e
LinuxLinux5.18

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-72261?
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control In snd_sof_update_control(), firmware-provided cdata->num_elems is checked against local_cdata->data->size but never against the actual allocation size. If local_cdata->data->size was previously set to an inconsistent value, the memcpy could write past the allocated buffer. Add a bounds check to ensure num_elems fits within the available space in the ipc_control_data allocation before copying.
How severe is CVE-2026-72261?
CVE-2026-72261 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.21% probability of exploitation in the next 30 days.
How do I fix CVE-2026-72261?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-72261?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST