Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-46179— ASoC: SOF: Don't allow pointer operations on unconfigured streams

AI Predicted 3.3 Difficulty: Moderate EPSS 0.02% · P5

Affected Version Matrix 12

VendorProductVersion RangeStatus
LinuxLinuxc1a731c71359407eae4fd0a5fd675ef25a582764< 327a64241f30c74b6f35537eb9e1fc6c3cbe060baffected
c1a731c71359407eae4fd0a5fd675ef25a582764< 98ed1383f597f8a45b6cb816bb20b96d46eecedaaffected
c1a731c71359407eae4fd0a5fd675ef25a582764< 0f0c0c1397a42aacaacae828206ee1b921623952affected
c1a731c71359407eae4fd0a5fd675ef25a582764< 4f42dd01f5217465f23a763e27b3984e114d0972affected
c1a731c71359407eae4fd0a5fd675ef25a582764< c5b6285aae050ff1c3ea824ca3d88ac4be1e69c8affected
6.1affected
< 6.1unaffected
6.6.140≤ 6.6.*unaffected
… +4 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46179

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ASoC: SOF: Don't allow pointer operations on unconfigured streams
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: Don't allow pointer operations on unconfigured streams When reporting the pointer for a compressed stream we report the current I/O frame position by dividing the position by the number of channels multiplied by the number of container bytes. These values default to 0 and are only configured as part of setting the stream parameters so this allows a divide by zero to be configured. Validate that they are non zero, returning an error if not
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于ASoC SOF中未配置流允许指针操作,可能导致除零错误。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux c1a731c71359407eae4fd0a5fd675ef25a582764 ~ 327a64241f30c74b6f35537eb9e1fc6c3cbe060b -
LinuxLinux 6.1 -

II. Public POCs for CVE-2026-46179

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46179

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46179 (5)

Same Patch Batch · Linux · 2026-05-28 · 138 CVEs total

CVE-2026-46190mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
CVE-2026-46207vsock/virtio: fix empty payload in tap skb for non-linear buffers
CVE-2026-46206batman-adv: reject new tp_meter sessions during teardown
CVE-2026-46205staging: media: atomisp: Disallow all private IOCTLs
CVE-2026-46204drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
CVE-2026-46203spi: cadence-quadspi: fix unclocked access on unbind
CVE-2026-46202HID: appletb-kbd: run inactivity autodim from workqueues
CVE-2026-46201drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()
CVE-2026-46200spi: mpc52xx: fix controller deregistration
CVE-2026-46199drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
CVE-2026-46198batman-adv: fix integer overflow on buff_pos
CVE-2026-46197drm/amdkfd: validate SVM ioctl nattr against buffer size
CVE-2026-46196tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
CVE-2026-46195smb: client: validate dacloffset before building DACL pointers
CVE-2026-46193xfrm: ah: account for ESN high bits in async callbacks
CVE-2026-46194f2fs: fix node_cnt race between extent node destroy and writeback
CVE-2026-46192spi: microchip-core-qspi: don't attempt to transmit during emulated read-only dual/quad op
CVE-2026-46191fbcon: Avoid OOB font access if console rotation fails
CVE-2026-46180wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
CVE-2026-46177ipmi: Add limits to event and receive message requests

Showing top 20 of 138 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-46179

No comments yet


Leave a comment