{"api_version":"1","generated_at":"2026-08-22T08:37:10+00:00","cve":"CVE-2026-74293","urls":{"html":"https://cve.report/CVE-2026-74293","api":"https://cve.report/api/cve/CVE-2026-74293.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-74293","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-74293"},"summary":{"title":"ASoC: fsl: fsl_audmix: Validate written enum values","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_audmix: Validate written enum values\n\nfsl_audmix_put_mix_clk_src() and fsl_audmix_put_out_src()\nconvert the user-provided enum item with snd_soc_enum_item_to_val()\nbefore checking whether the item is within the enum's item count.\n\nThe generic snd_soc_put_enum_double() helper performs that\nvalidation, but these callbacks use the converted value first: the\nclock-source path tests it with BIT(), and the output-source path\nindexes the prms transition table with it.\n\nReject out-of-range enum items before converting them.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-15 06:22:28","updated_at":"2026-08-17 06:19:23"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3","name":"https://git.kernel.org/stable/c/8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7513831b90a38d55fa089e3e1b49691e467afee6","name":"https://git.kernel.org/stable/c/7513831b90a38d55fa089e3e1b49691e467afee6","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0b10c6203e62d9e7337cc401568b201f9bac79ec","name":"https://git.kernel.org/stable/c/0b10c6203e62d9e7337cc401568b201f9bac79ec","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b36d6d48faa6b1bb723b8f4e527c531a1a68520e","name":"https://git.kernel.org/stable/c/b36d6d48faa6b1bb723b8f4e527c531a1a68520e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b4774a7da12b14fc37219ab4368d1907f9b5aca4","name":"https://git.kernel.org/stable/c/b4774a7da12b14fc37219ab4368d1907f9b5aca4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/3cd17e4e2871114d5579fa7bc8da66faf7fc1930","name":"https://git.kernel.org/stable/c/3cd17e4e2871114d5579fa7bc8da66faf7fc1930","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c","name":"https://git.kernel.org/stable/c/0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a","name":"https://git.kernel.org/stable/c/5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-74293","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-74293","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected be1df61cf06efb355c90702e46b8d46f055acb4e 7513831b90a38d55fa089e3e1b49691e467afee6 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected be1df61cf06efb355c90702e46b8d46f055acb4e b4774a7da12b14fc37219ab4368d1907f9b5aca4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected be1df61cf06efb355c90702e46b8d46f055acb4e 8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected be1df61cf06efb355c90702e46b8d46f055acb4e 0b10c6203e62d9e7337cc401568b201f9bac79ec git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected be1df61cf06efb355c90702e46b8d46f055acb4e b36d6d48faa6b1bb723b8f4e527c531a1a68520e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected be1df61cf06efb355c90702e46b8d46f055acb4e 0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected be1df61cf06efb355c90702e46b8d46f055acb4e 5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected be1df61cf06efb355c90702e46b8d46f055acb4e 3cd17e4e2871114d5579fa7bc8da66faf7fc1930 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 5.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.261 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.212 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.178 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.145 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.97 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.40 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.5 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"74293","cve":"CVE-2026-74293","epss":"0.001290000","percentile":"0.029820000","score_date":"2026-08-17","updated_at":"2026-08-18 00:11:46"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["sound/soc/fsl/fsl_audmix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"7513831b90a38d55fa089e3e1b49691e467afee6","status":"affected","version":"be1df61cf06efb355c90702e46b8d46f055acb4e","versionType":"git"},{"lessThan":"b4774a7da12b14fc37219ab4368d1907f9b5aca4","status":"affected","version":"be1df61cf06efb355c90702e46b8d46f055acb4e","versionType":"git"},{"lessThan":"8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3","status":"affected","version":"be1df61cf06efb355c90702e46b8d46f055acb4e","versionType":"git"},{"lessThan":"0b10c6203e62d9e7337cc401568b201f9bac79ec","status":"affected","version":"be1df61cf06efb355c90702e46b8d46f055acb4e","versionType":"git"},{"lessThan":"b36d6d48faa6b1bb723b8f4e527c531a1a68520e","status":"affected","version":"be1df61cf06efb355c90702e46b8d46f055acb4e","versionType":"git"},{"lessThan":"0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c","status":"affected","version":"be1df61cf06efb355c90702e46b8d46f055acb4e","versionType":"git"},{"lessThan":"5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a","status":"affected","version":"be1df61cf06efb355c90702e46b8d46f055acb4e","versionType":"git"},{"lessThan":"3cd17e4e2871114d5579fa7bc8da66faf7fc1930","status":"affected","version":"be1df61cf06efb355c90702e46b8d46f055acb4e","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["sound/soc/fsl/fsl_audmix.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"5.2"},{"lessThan":"5.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.261","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.212","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.178","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.145","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.97","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.40","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.5","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.261","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.212","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.178","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.145","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.97","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.40","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.5","versionStartIncluding":"5.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"5.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_audmix: Validate written enum values\n\nfsl_audmix_put_mix_clk_src() and fsl_audmix_put_out_src()\nconvert the user-provided enum item with snd_soc_enum_item_to_val()\nbefore checking whether the item is within the enum's item count.\n\nThe generic snd_soc_put_enum_double() helper performs that\nvalidation, but these callbacks use the converted value first: the\nclock-source path tests it with BIT(), and the output-source path\nindexes the prms transition table with it.\n\nReject out-of-range enum items before converting them."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires a local SNDRV_CTL_IOCTL_ELEM_WRITE to /dev/snd/controlC* for the fsl-audmix \"Output Source\" or \"Mixing Clock Source\" mixer controls; no network, Bluetooth, or physical-input path reaches these put callbacks.\nAC:L - On default builds without CONFIG_SND_CTL_INPUT_VALIDATION, a single ioctl supplying an out-of-range enumerated.item[0] deterministically reaches the buggy snd_soc_enum_item_to_val()/prms[] indexing before snd_soc_put_enum_double() rejects the value; no race or uncontrollable state is needed.\nPR:L - snd_ctl_open() and snd_ctl_elem_write() perform no capability or namespace checks; any local user with ordinary access to the ALSA control device (common on i.MX8QM/i.MX952 automotive/embedded systems via audio-group or seat ACLs) can trigger the vulnerable callbacks.\nUI:N - The attacker issues the control write from its own process after opening the control device; no separate victim action such as mounting a filesystem or opening a file is required.\nS:U - The flaw corrupts or misreads kernel data and programs on-chip AUDMIX MMIO within the same host kernel security authority; it does not cross a VM, IOMMU, or sandbox boundary.\nC:H - Out-of-range enum indices are used to index the static prms[out_src][val] transition table and in BIT(val) before bounds checks, causing out-of-bounds reads of kernel rodata that are copied into transition state and can disclose adjacent memory contents.\nI:H - Attacker-chosen indices can select unintended prms transition cells or out-of-bounds prm data that pass fsl_audmix_state_trans() and drive snd_soc_component_update_bits() to write attacker-influenced mask/ctr values into AUDMIX hardware control registers.\nA:H - Large enum values can provoke undefined BIT() shifts, read past the prms table boundary, and program invalid AUDMIX control-register states that can kernel-fault or hang the audio subsystem; conservative scoring treats this memory-corruption class as high availability impact."}]}],"providerMetadata":{"dateUpdated":"2026-08-17T05:45:31.193Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/7513831b90a38d55fa089e3e1b49691e467afee6"},{"url":"https://git.kernel.org/stable/c/b4774a7da12b14fc37219ab4368d1907f9b5aca4"},{"url":"https://git.kernel.org/stable/c/8fb4364eb494b926d009bfaf3c98f07c3aa5d9f3"},{"url":"https://git.kernel.org/stable/c/0b10c6203e62d9e7337cc401568b201f9bac79ec"},{"url":"https://git.kernel.org/stable/c/b36d6d48faa6b1bb723b8f4e527c531a1a68520e"},{"url":"https://git.kernel.org/stable/c/0f1510e84d7bfc3eb9538efa65c6ea0aadf1078c"},{"url":"https://git.kernel.org/stable/c/5b7a23c1ed04e794ef3b31e452ef5c93e1e34b4a"},{"url":"https://git.kernel.org/stable/c/3cd17e4e2871114d5579fa7bc8da66faf7fc1930"}],"title":"ASoC: fsl: fsl_audmix: Validate written enum values","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-74293","datePublished":"2026-08-15T05:57:58.889Z","dateReserved":"2026-08-15T05:44:03.881Z","dateUpdated":"2026-08-17T05:45:31.193Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-15 06:22:28","lastModifiedDate":"2026-08-17 06:19:23","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"74293","Ordinal":"1","Title":"ASoC: fsl: fsl_audmix: Validate written enum values","CVE":"CVE-2026-74293","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"74293","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: fsl: fsl_audmix: Validate written enum values\n\nfsl_audmix_put_mix_clk_src() and fsl_audmix_put_out_src()\nconvert the user-provided enum item with snd_soc_enum_item_to_val()\nbefore checking whether the item is within the enum's item count.\n\nThe generic snd_soc_put_enum_double() helper performs that\nvalidation, but these callbacks use the converted value first: the\nclock-source path tests it with BIT(), and the output-source path\nindexes the prms transition table with it.\n\nReject out-of-range enum items before converting them.","Type":"Description","Title":"ASoC: fsl: fsl_audmix: Validate written enum values"}]}}}