ReviewHigh

CVE-2026-80583

Linux

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type") and commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.08.27
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type") and commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of...

Affected product and versions

Product
Linux
Affected versions
>= c39667ddcfc516fee084e449179d54430a558298 < dbc81b518f6936131bfd858be71cd4295136809c, >= c39667ddcfc516fee084e449179d54430a558298 < f84f2c81d792cf1e65571108a3bdd2c29e09e995, >= c39667ddcfc516fee084e449179d54430a558298 < 48b76879f5bfc8584b99052510ac645c6ade8d2b, >= c39667ddcfc516fee084e449179d54430a558298 < 2ed3601e9db08fbdb071bd3d7bd8f115d6d871b0, >= c39667ddcfc516fee084e449179d54430a558298 < b6baab796d11fb84c0e9444ffca91af5eab22c25, >= c39667ddcfc516fee084e449179d54430a558298 < 3ee3c26ceee562079596abc9bc3307dd56dab4ed, >= c39667ddcfc516fee084e449179d54430a558298 < 1ba381759e45d5d0442452cfa5c42e836191a568, >= 5.12
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available