PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72301 Linux CVE debrief

A use-after-free vulnerability was discovered in the Linux kernel's ASoC (Advanced System on Chip) SOF (Sound Open Firmware) ipc3-control module. The vulnerability arises from a timing issue (TOCTOU, or Time-of-Check-to-Time-of-Use) in the `bytes_put` and `bytes_get` functions. In `sof_ipc3_bytes_put()`, the size used for the memcpy operation is derived from the old `data->size` already in the buffer, rather than the size of the incoming new data. This can lead to incorrect copy lengths, potentially truncating valid data or copying stale bytes. In `sof_ipc3_bytes_get()`, the function checks `data->size` against `max_size` without accounting for the offset of the flex array within the allocation, which can also lead to incorrect handling of data. The issue has been resolved by validating and using the incoming data's `sof_abi_hdr.size` in `bytes_put`, and by subtracting the size of `struct sof_ipc_ctrl_data` from the bounds check in `bytes_get` to match the actual available space.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers, Linux distribution maintainers, and users of Linux-based systems should be aware of this vulnerability and take steps to mitigate it. Additionally, organizations that use Linux-based systems in their infrastructure should also be aware of this vulnerability and take steps to protect their systems.

Technical summary

The vulnerability is caused by a TOCTOU issue in the `bytes_put` and `bytes_get` functions of the ASoC SOF ipc3-control module in the Linux kernel. The `bytes_put` function uses the old `data->size` to determine the copy length, rather than the size of the incoming new data. The `bytes_get` function checks `data->size` against `max_size` without accounting for the offset of the flex array within the allocation. This can lead to incorrect handling of data, potentially allowing for privilege escalation and control of affected systems.

Defensive priority

This vulnerability has a high defensive priority due to its potential impact on system stability and security. Linux kernel vulnerabilities can be particularly dangerous as they can allow for privilege escalation and control of affected systems.

Recommended defensive actions

  • Review and apply the provided patches to the Linux kernel to fix the vulnerability
  • Ensure that the Linux kernel is updated to a version that includes the fix
  • Monitor system logs for potential exploitation attempts
  • Implement additional security controls, such as SELinux or AppArmor, to limit the impact of a potential exploit
  • Perform a thorough review of system configurations to ensure that they align with security best practices
  • Verify that all necessary security updates are applied and that the system is running with the latest security patches
  • Track and document changes to the system and its configurations to ensure accountability and facilitate future audits

Evidence notes

The evidence for this vulnerability is based on the official CVE record and the NVD detail page. The CVE record provides a brief description of the vulnerability, while the NVD detail page offers additional information on the vulnerability's impact and potential mitigations. However, due to limited information available, further verification and validation are necessary to fully understand the vulnerability's scope and impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72301 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72301

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72301 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72301

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0c4fbdaca225b97122b61b68c5353caa33a253c3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0dce240145f47545d2e4b18c6d58033b83e1fd0e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1f97760417b5faa60e9642fd0ed61eb17d0b1b39

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/8bd715a9d882fe1993bb2aec5eff89fffa946592

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/92f90917413bdd6078fefff6f6c83a07bf870b04

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/ed4f758f34be4c32e02933ac4fa044589d9c1c16

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.