CVE EVIDENCE REVIEW
ReviewHighEvidence review

CVE-2026-80583 evidence review

Linux

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type") and commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of...

Open CVE record
Evidence review

This record remains available for product and version identification, but it is not presented as a complete remediation procedure. Confirm the affected range and the supported fix in a direct vendor advisory before changing production systems.

ProductLinux
Affected versions>= c39667ddcfc516fee084e449179d54430a558298 < dbc81b518f6936131bfd858be71cd4295136809c, >= c39667ddcfc516fee084e449179d54430a558298 < f84f2c81d792cf1e65571108a3bdd2c29e09e995, >= c39667ddcfc516fee084e449179d54430a558298 < 48b76879f5bfc8584b99052510ac645c6ade8d2b, >= c39667ddcfc516fee084e449179d54430a558298 < 2ed3601e9db08fbdb071bd3d7bd8f115d6d871b0, >= c39667ddcfc516fee084e449179d54430a558298 < b6baab796d11fb84c0e9444ffca91af5eab22c25, >= c39667ddcfc516fee084e449179d54430a558298 < 3ee3c26ceee562079596abc9bc3307dd56dab4ed, >= c39667ddcfc516fee084e449179d54430a558298 < 1ba381759e45d5d0442452cfa5c42e836191a568, >= 5.12
Fixed versionsNo verified fixed-version field is available yet
Priority basisReview · CVSS 7.8 · EPSS -
01

Identify the product and installed version

Record whether Linux is present, where it is installed, and which interfaces are exposed.

  • Record the product name, package or appliance identifier, and installed version.
  • Identify internet-facing, administrative, API, and internal access paths.
  • Preserve the pre-change configuration and relevant service logs.
02

Compare the affected range

Use the current record as an identification aid: >= c39667ddcfc516fee084e449179d54430a558298 < dbc81b518f6936131bfd858be71cd4295136809c, >= c39667ddcfc516fee084e449179d54430a558298 < f84f2c81d792cf1e65571108a3bdd2c29e09e995, >= c39667ddcfc516fee084e449179d54430a558298 < 48b76879f5bfc8584b99052510ac645c6ade8d2b, >= c39667ddcfc516fee084e449179d54430a558298 < 2ed3601e9db08fbdb071bd3d7bd8f115d6d871b0, >= c39667ddcfc516fee084e449179d54430a558298 < b6baab796d11fb84c0e9444ffca91af5eab22c25, >= c39667ddcfc516fee084e449179d54430a558298 < 3ee3c26ceee562079596abc9bc3307dd56dab4ed, >= c39667ddcfc516fee084e449179d54430a558298 < 1ba381759e45d5d0442452cfa5c42e836191a568, >= 5.12. Resolve incomplete inventory results before deciding that an asset is unaffected.

03

Verify the authoritative remediation source

Open the linked source material and locate a direct vendor advisory for this CVE. Confirm the supported fixed release and product-specific update path before making a production change.

Operational boundary

This page does not replace the vendor advisory, support contract, change-management process, or recovery plan. Do not infer that an asset is unaffected from an incomplete inventory query or a missing fixed-version field.