PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72415 Linux CVE debrief

The Linux kernel has a vulnerability in the ASoC SDCA component. The ge_put_enum_double() function does not validate the user-supplied enumeration index before passing it to snd_soc_enum_item_to_val(), which can lead to reading past the end of the values buffer. This issue has been resolved by adding a bounds check to reject out-of-range items before using them.

Vendor
Linux
Product
Unknown
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-15
Original CVE updated
2026-08-15
Advisory published
2026-08-15
Advisory updated
2026-08-15

Who should care

Linux kernel developers and users, ASoC SDCA component users, and security teams responsible for vulnerability management and patching should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability affects the Linux kernel's ASoC SDCA component, and users of this component should review and apply the patch to the Linux kernel. Additionally, operators and platform administrators should be aware of the potential impact on their systems and take steps to verify and mitigate the vulnerability.

Technical summary

The ge_put_enum_double() function in the Linux kernel's ASoC SDCA component does not validate the user-supplied enumeration index before passing it to snd_soc_enum_item_to_val(). This can lead to reading past the end of the values buffer. The issue has been resolved by adding a bounds check to reject out-of-range items before using them. The affected product is the Linux kernel, and the vulnerability has a medium defensive priority. The technical impact is that an attacker could potentially exploit this vulnerability to read past the end of the values buffer, which could lead to a denial of service or other unspecified impacts.

Defensive priority

Medium

Recommended defensive actions

  • Review and apply the patch to the Linux kernel
  • Validate user-supplied enumeration indices in the ge_put_enum_double() function
  • Monitor for potential exploits of this vulnerability
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The vulnerability was pointed out by the Sashiko AI review bot while reviewing a related enum-validation series. The issue is in the ge_put_enum_double() function, which does not validate the user-supplied enumeration index before using it. To verify, defenders should review the Linux kernel's ASoC SDCA component and check for potential exploits of this vulnerability. The Sashiko AI review bot's findings indicate that the ge_put_enum_double() function passes the user-supplied enumeration index item[0] to snd_soc_enum_item_to_val() without checking it against the number of items in the enum. This can lead to reading past the end of the values buffer. The bounds check in snd_soc_dapm_put_enum_double() only runs afterwards, so it does not prevent the read here. The issue has been resolved by adding a bounds check to reject out-of-range items before using them.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72415 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72415

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72415 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72415

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1ce42a11bed134903e352010a01fa53073a6b395

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/33387bf9bb6116a0429f823f8dab3accf8f8e09c

    416baaa9-dc9f-4396-8d5f-8c081fb06d67

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.