PT-2026-98716 · Linux · Linux

CVE-2026-98053

·

Published

2026-09-25

·

Updated

2026-09-25

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
ASoC: Intel: avs: Refactor and fix init config access
Existing code accesses enties found in ->init configs array through indexes that are part of ->config ids array. Those two are limited by: ->num init configs and ->num config ids respectively. Using ID larger or equal to ->num init configs leads to out-of-bounds access:
avs path module send init configs() loop: (...) &acomp->tplg->init configs[ids[i]] ^ out-of-bounds candidate
Rather than adding another if-statement, refactor the code. There is no need to store the IDs, have a list of pointers to actual config-entries instead. As the verification of ->init config entries does not differ from verification of other types that are part of the topology.c file, simply reuse the code.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98053

Affected Products

Linux