PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-43480 Linux CVE debrief

CVE-2026-43480 covers a Linux kernel ASoC bug in the AMD ACP3x RT5682/MAX9836 audio path. The driver failed to check whether clock acquisition succeeded, which could let an error pointer reach later clock-enable logic. The fix switches to managed clock acquisition and adds proper error handling.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-13
Original CVE updated
2026-06-26
Advisory published
2026-05-13
Advisory updated
2026-06-26

Who should care

Linux kernel maintainers, distro security teams, OEMs, and operators of systems using AMD ACP3x audio with RT5682/MAX9836 codecs.

Technical summary

The acp3x_5682_init() path used clk_get() without validating the return value. If clock acquisition failed, rt5682_clk_enable() could dereference an error pointer in kernel space, which is an availability risk and may crash affected systems. The remediation changes the code to devm_clk_get() and adds IS_ERR() checks for both clock acquisitions.

Defensive priority

Medium to high for deployments that include the affected AMD audio hardware; low for systems that do not use this driver path.

Recommended defensive actions

  • Verify whether your kernel branch includes the stable backport(s) referenced in the NVD record.
  • Update affected kernels on AMD ACP3x + RT5682/MAX9836 systems to a build that contains the fix.
  • Monitor affected devices for audio initialization failures, kernel warnings, or crashes after remediation.
  • Track distro or OEM advisories for any additional backports specific to your release line.

Evidence notes

The supplied corpus includes the official CVE/NVD records plus kernel.org stable commit references, but no CVSS vector or full diff text. The debrief therefore stays limited to the documented flaw: missing clock-acquisition error checks that could lead to error-pointer dereference in kernel code.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-43480 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-43480

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-43480 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43480

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/092522621901b5e6af61db04a53f5b313903c6d0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2b0c4a399c8d27f20ecf17dda76751141d6dbb59

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/33de168afdd57265a0e0c20dbd3648a2d8f7cdc4

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/35c7624d30cb45ec336cd16ce072acc32ae351cb

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/4d802f23fcbfec05134653fd001f6c7c3fd55196

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/53f3a900e9a383d47af7253076e19f510c5708d0

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.