{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-89943","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-09-11T19:38:34.777Z","datePublished":"2026-09-16T10:32:30.527Z","dateUpdated":"2026-09-16T14:40:31.281Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-09-16T14:40:31.281Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: loongson: Fix error handling in ACPI property parsing\n\nIn loongson_card_parse_acpi(), the return value of\ndevice_property_read_string() for the `codec-dai-name` property was\nignored. If the property is missing or invalid, an uninitialized pointer\nwould be used later, potentially leading to undefined behavior.\n\nFix this by checking the return value and propagating the error\nappropriately."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The bug is in loongson_card_parse_acpi(), reached only from the Loongson ASoC platform probe (loongson_asoc_card_probe) when an ACPI-companion sound-card device is enumerated. There is no network, Bluetooth, or USB packet path into this ACPI property parser.\nAC:L - If the codec-dai-name ACPI property is missing or not a string, device_property_read_string() fails without writing codec_dai_name; the ignored return then deterministically stores that uninitialized pointer into the static DAI link. No race or attacker-uncontrollable layout is required.\nPR:N - loongson_asoc_card_probe() runs automatically from ACPI/platform enumeration (PRP0001 compatible loongson,ls-audio-card) on Loongson laptops, embedded boards, and LoongArch VMs; no OS account, capability, or user-namespace privilege is checked on this probe path.\nUI:N - Probe and deferred-probe retries run unattended at boot when the matching ACPI audio-card device is present; no victim must open ALSA nodes, load a module by hand, or plug in extra hardware.\nS:U - The uninitialized DAI-name pointer is consumed inside the host ASoC core (DAI matching and logging) on the same kernel security authority; this is not a VM escape, IOMMU bypass, or sandbox breakout.\nC:H - The garbage pointer is stored as codecs->dai_name and later passed to strcmp() in snd_soc_is_matching_dai() and to %s in the CODEC DAI not-registered log, producing an unbounded kernel-memory read rather than a small bounded leak.\nI:H - The same uninitialized stack pointer is written into static loongson_dai_links[] used for DAI matching; a wild-pointer match binds the wrong codec DAI (type confusion) and later ASoC bring-up operates through that component, an exploitable integrity primitive consistent with uninitialized-pointer scoring.\nA:H - strcmp() or printk %s on the uninitialized pointer oopses or panics the kernel during sound-card probe on affected Loongson ACPI systems, fully denying availability."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/soc/loongson/loongson_card.c"],"versions":[{"version":"ddb538a3004b10a04a14a0d275c5f52a8d161e80","lessThan":"682c123cef455545f48ecbe74b3872fa303bf58f","status":"affected","versionType":"git"},{"version":"ddb538a3004b10a04a14a0d275c5f52a8d161e80","lessThan":"4e580d84a638f007b5b68d50d7633de502f325e7","status":"affected","versionType":"git"},{"version":"ddb538a3004b10a04a14a0d275c5f52a8d161e80","lessThan":"bb1602908c67db7197ab001638573262bccc6ca2","status":"affected","versionType":"git"},{"version":"ddb538a3004b10a04a14a0d275c5f52a8d161e80","lessThan":"0eb0e3c623ac1da8b85d518043fef7660af7805d","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/soc/loongson/loongson_card.c"],"versions":[{"version":"6.12","status":"affected"},{"version":"0","lessThan":"6.12","status":"unaffected","versionType":"semver"},{"version":"6.12.110","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.51","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.2.5","lessThanOrEqual":"7.2.*","status":"unaffected","versionType":"semver"},{"version":"7.3-rc1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.12.110"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"6.18.51"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.2.5"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12","versionEndExcluding":"7.3-rc1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/682c123cef455545f48ecbe74b3872fa303bf58f"},{"url":"https://git.kernel.org/stable/c/4e580d84a638f007b5b68d50d7633de502f325e7"},{"url":"https://git.kernel.org/stable/c/bb1602908c67db7197ab001638573262bccc6ca2"},{"url":"https://git.kernel.org/stable/c/0eb0e3c623ac1da8b85d518043fef7660af7805d"}],"title":"ASoC: loongson: Fix error handling in ACPI property parsing","x_generator":{"engine":"bippy-1.2.0"}}}}