{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-74295","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-15T05:44:03.882Z","datePublished":"2026-08-15T05:58:00.123Z","dateUpdated":"2026-08-17T05:45:33.387Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T05:45:33.387Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: codecs: hdac_hdmi: Validate written enum value\n\nhdac_hdmi_set_pin_port_mux() uses the written enum value to index the\ntexts array before calling snd_soc_dapm_put_enum_double(), which validates\nthat the value is within the enum item range.\n\nAn out-of-range value can therefore make the driver read past the texts\narray before the helper rejects the write. Move the lookup after the helper\nhas accepted the value."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","baseScore":7.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is reached only through local ALSA control ioctls on /dev/snd/controlC* (SNDRV_CTL_IOCTL_ELEM_WRITE), which invoke hdac_hdmi_set_pin_port_mux(); there is no network, Bluetooth, or physical-input path to this callback.\nAC:L - An attacker with access to the ALSA control device can supply any out-of-range enumerated.item[0] value and reliably trigger the out-of-bounds texts[] read on default kernels without CONFIG_SND_CTL_INPUT_VALIDATION, without races or other uncontrollable conditions.\nPR:L - Exploitation requires local access to the ALSA control device (/dev/snd/controlC*), typically granted to the logged-in desktop user or audio group; no CAP_SYS_ADMIN or real root is required and user namespaces do not gate this path.\nUI:N - Once the attacker has ALSA control-device access, they can issue the ioctl directly to the Pin port Input mux control without requiring any action from another user or victim.\nS:U - The vulnerable Intel HDMI/DP audio codec driver and resulting kernel memory impacts remain within the host kernel security authority and do not cross VM, container, or IOMMU security boundaries.\nC:H - The unchecked enum index performs an out-of-bounds read of e->texts[], loading attacker-chosen adjacent kernel heap memory as a char* before validation rejects the write; per conservative kernel guidance, out-of-bounds reads are scored High.\nI:N - The bug is a read-only out-of-bounds array access with no out-of-bounds write, heap corruption, or attacker-controlled modification; snd_soc_dapm_put_enum_double() rejects invalid values before persisting any mux state change.\nA:H - Attacker-controlled out-of-bounds indices can load texts[] from unmapped addresses and fault the kernel during the pointer fetch; even near-boundary reads are a memory-safety violation treated conservatively as potential denial-of-service on affected Intel HDMI systems."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/soc/codecs/hdac_hdmi.c"],"versions":[{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"216336418c007c4b44c650acf2fd3d2de5bb81e8","status":"affected","versionType":"git"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"bc464a6a9e352daa17b1636c090cf3185710b9a0","status":"affected","versionType":"git"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"8cbf24714d6b3f553fc959632c9781176a73a9a7","status":"affected","versionType":"git"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"7f02e9064b6f84e7f93c72f134306271eb4f7de4","status":"affected","versionType":"git"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"9131e4b023e0db5764680034bdc94aeae0b0f33d","status":"affected","versionType":"git"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"d8961b5c7889b6ecc00f1409d36826df1665df27","status":"affected","versionType":"git"},{"version":"4a3478debf36c0aa0cf0860daec245b13cd4448f","lessThan":"0b08baeccdcf52fad328ad645f5b4fbee04eea34","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/soc/codecs/hdac_hdmi.c"],"versions":[{"version":"4.6","status":"affected"},{"version":"0","lessThan":"4.6","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.40","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.5","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"6.18.40"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"7.1.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.6","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/216336418c007c4b44c650acf2fd3d2de5bb81e8"},{"url":"https://git.kernel.org/stable/c/bc464a6a9e352daa17b1636c090cf3185710b9a0"},{"url":"https://git.kernel.org/stable/c/8cbf24714d6b3f553fc959632c9781176a73a9a7"},{"url":"https://git.kernel.org/stable/c/7f02e9064b6f84e7f93c72f134306271eb4f7de4"},{"url":"https://git.kernel.org/stable/c/9131e4b023e0db5764680034bdc94aeae0b0f33d"},{"url":"https://git.kernel.org/stable/c/d8961b5c7889b6ecc00f1409d36826df1665df27"},{"url":"https://git.kernel.org/stable/c/0b08baeccdcf52fad328ad645f5b4fbee04eea34"}],"title":"ASoC: codecs: hdac_hdmi: Validate written enum value","x_generator":{"engine":"bippy-1.2.0"}}}}