CVE-2026-80583
Received Received - Intake

ASoC Codec Enum Access Flaw in Linux Kernel

Vulnerability report for CVE-2026-80583, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type") and commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of bounds for enum type"), but tx-macro was missed. On 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value sanity check catches the 4 bytes written past the enumerated item and every read of these controls fails with -EINVAL: snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
linux linux_kernel *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves incorrect handling of enumerated controls in the lpass-tx-macro codec driver. The issue occurs because the functions tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access enum control values as integers instead of enumerated types, leading to out-of-bounds memory access.

Detection Guidance

This vulnerability affects the Linux kernel's ASoC codec drivers, specifically the lpass-tx-macro component. Detection requires checking kernel logs for errors related to sound control access failures. Look for messages like 'access overflow' in dmesg or journalctl logs. No network-specific detection is needed as this is a local kernel issue.

Impact Analysis

On 64-bit kernels with CONFIG_SND_CTL_DEBUG enabled, this flaw causes read operations of affected controls to fail with -EINVAL errors. It may lead to sound subsystem malfunctions or crashes when accessing specific audio controls.

Mitigation Strategies

Update your Linux kernel to a patched version that includes the fix for this issue. The vulnerability is resolved in newer kernels, so applying the latest stable kernel update is the primary mitigation step. No configuration changes are required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80583. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart