PatchSiren cyber security CVE debrief
CVE-2026-43480 Linux CVE debrief
CVE-2026-43480 covers a Linux kernel ASoC bug in the AMD ACP3x RT5682/MAX9836 audio path. The driver failed to check whether clock acquisition succeeded, which could let an error pointer reach later clock-enable logic. The fix switches to managed clock acquisition and adds proper error handling.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-13
- Original CVE updated
- 2026-06-26
- Advisory published
- 2026-05-13
- Advisory updated
- 2026-06-26
Who should care
Linux kernel maintainers, distro security teams, OEMs, and operators of systems using AMD ACP3x audio with RT5682/MAX9836 codecs.
Technical summary
The acp3x_5682_init() path used clk_get() without validating the return value. If clock acquisition failed, rt5682_clk_enable() could dereference an error pointer in kernel space, which is an availability risk and may crash affected systems. The remediation changes the code to devm_clk_get() and adds IS_ERR() checks for both clock acquisitions.
Defensive priority
Medium to high for deployments that include the affected AMD audio hardware; low for systems that do not use this driver path.
Recommended defensive actions
- Verify whether your kernel branch includes the stable backport(s) referenced in the NVD record.
- Update affected kernels on AMD ACP3x + RT5682/MAX9836 systems to a build that contains the fix.
- Monitor affected devices for audio initialization failures, kernel warnings, or crashes after remediation.
- Track distro or OEM advisories for any additional backports specific to your release line.
Evidence notes
The supplied corpus includes the official CVE/NVD records plus kernel.org stable commit references, but no CVSS vector or full diff text. The debrief therefore stays limited to the documented flaw: missing clock-acquisition error checks that could lead to error-pointer dereference in kernel code.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43480 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43480
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43480 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43480
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/092522621901b5e6af61db04a53f5b313903c6d0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2b0c4a399c8d27f20ecf17dda76751141d6dbb59
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/33de168afdd57265a0e0c20dbd3648a2d8f7cdc4
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/35c7624d30cb45ec336cd16ce072acc32ae351cb
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/4d802f23fcbfec05134653fd001f6c7c3fd55196
416baaa9-dc9f-4396-8d5f-8c081fb06d67
-
Source reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/53f3a900e9a383d47af7253076e19f510c5708d0
416baaa9-dc9f-4396-8d5f-8c081fb06d67
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.