{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74293","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.881Z","datePublished":"2026-08-15T05:57:58.889Z","dateUpdated":"2026-08-17T05:45:31.193Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:45:31.193Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_audmix: Validate written enum values\n\nfsl_audmix_put_mix_clk_src() and fsl_audmix_put_out_src()\nconvert the user-provided enum item with snd_soc_enum_item_to_val()\nbefore checking whether the item is within the enum's item count.\n\nThe generic snd_soc_put_enum_double() helper performs that\nvalidation, but these callbacks use the converted value first: the\nclock-source path tests it with BIT(), and the output-source path\nindexes the prms transition table with it.\n\nReject out-of-range enum items before converting them."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires a local SNDRV_CTL_IOCTL_ELEM_WRITE to /dev/snd/controlC* for the fsl-audmix \"Output Source\" or \"Mixing Clock Source\" mixer controls; no network, Bluetooth, or physical-input path reaches these put callbacks.\nAC:L - On default builds without CONFIG_SND_CTL_INPUT_VALIDATION, a single ioctl supplying an out-of-range enumerated.item[0] deterministically reaches the buggy snd_soc_enum_item_to_val()/prms[] indexing before snd_soc_put_enum_double() rejects the value; no race or uncontrollable state is needed.\nPR:L - snd_ctl_open() and snd_ctl_elem_write() perform no capability or namespace checks; any local user with ordinary access to the ALSA control device (common on i.MX8QM/i.MX952 automotive/embedded systems via audio-group or seat ACLs) can trigger the vulnerable callbacks.\nUI:N - The attacker issues the control write from its own process after opening the control device; no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - The flaw corrupts or misreads kernel data and programs on-chip AUDMIX MMIO within the same host kernel security authority; it does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Out-of-range enum indices are used to index the static prms[out_src][val] transition table and in BIT(val) before bounds checks, causing out-of-bounds reads of kernel rodata that are copied into transition state and can disclose adjacent memory contents.\nI:H - Attacker-chosen indices can select unintended prms transition cells or out-of-bounds prm data that pass fsl_audmix_state_trans() and drive snd_soc_component_update_bits() to write attacker-influenced mask/ctr values into AUDMIX hardware control registers.\nA:H - Large enum values can provoke undefined BIT() shifts, read past the prms table boundary, and program invalid AUDMIX control-register states that can kernel-fault or hang the audio subsystem; conservative scoring treats this memory-corruption class as high availability impact."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/soc/fsl/fsl_audmix.c"],"versions":[{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"7513831b90a38d55fa089e3e1b49691e467afee6","status":"affected","versionType":"git"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"b4774a7da12b14fc37219ab4368d1907f9b5aca4","status":"affected","versionType":"git"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3","status":"affected","versionType":"git"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"0b10c6203e62d9e7337cc401568b201f9bac79ec","status":"affected","versionType":"git"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"b36d6d48faa6b1bb723b8f4e527c531a1a68520e","status":"affected","versionType":"git"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c","status":"affected","versionType":"git"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a","status":"affected","versionType":"git"},{"version":"be1df61cf06efb355c90702e46b8d46f055acb4e","lessThan":"3cd17e4e2871114d5579fa7bc8da66faf7fc1930","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/soc/fsl/fsl_audmix.c"],"versions":[{"version":"5.2","status":"affected"},{"version":"0","lessThan":"5.2","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.2","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/7513831b90a38d55fa089e3e1b49691e467afee6"},{"url":"https://git.kernel.org/stable/c/b4774a7da12b14fc37219ab4368d1907f9b5aca4"},{"url":"https://git.kernel.org/stable/c/8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3"},{"url":"https://git.kernel.org/stable/c/0b10c6203e62d9e7337cc401568b201f9bac79ec"},{"url":"https://git.kernel.org/stable/c/b36d6d48faa6b1bb723b8f4e527c531a1a68520e"},{"url":"https://git.kernel.org/stable/c/0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c"},{"url":"https://git.kernel.org/stable/c/5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a"},{"url":"https://git.kernel.org/stable/c/3cd17e4e2871114d5579fa7bc8da66faf7fc1930"}],"title":"ASoC: fsl: fsl_audmix: Validate written enum values","x_generator":{"engine":"bippy-1.2.0"}}}}