PT-2026-97967 · Linux · Linux Kernel
CVE-2026-93280
·
Published
2026-09-24
·
Updated
2026-09-28
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An issue exists in the greybus audio component where the
gb audio gb get topology() function fetches a topology blob based on a size supplied by a module. The gbaudio tplg parse data() function then calculates offsets for control, widget, and route sections by adding the module-supplied size dais, size controls, and size widgets fields. Because these sizes are not validated against the actual fetched blob size, a module providing a small topology size but large section sizes can cause the offsets to point beyond the allocated memory, leading to an out-of-bounds read during parsing.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel