PT-2026-54818 · Linux+1 · Linux Kernel+1
CVE-2026-53350
·
Published
2026-07-01
·
Updated
2026-09-07
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A NULL dereference occurs in the ASOC wm adsp component during the removal of firmware controls. The function
wm adsp control remove() attempts to clean up private data pointed to by the priv variable without verifying if the pointer is NULL. This situation arises when private data is not created, which happens if the control is a SYSTEM control or if the codec driver has a control add() callback that hides the control, preventing wm adsp control add() from being called. When cs dsp remove() destroys the control list, it triggers wm adsp control remove(), leading to the crash.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel
Ubuntu