Bug 2540309 (CVE-2026-93280) - CVE-2026-93280 kernel: greybus: audio: bound the topology section sizes against the fetched size
Summary: CVE-2026-93280 kernel: greybus: audio: bound the topology section sizes again...
Keywords:
Status: NEW
Alias: CVE-2026-93280
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 16:19 UTC by OSIDB Bzimport
Modified: 2026-09-28 13:34 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 16:19:02 UTC
In the Linux kernel, the following vulnerability has been resolved:

greybus: audio: bound the topology section sizes against the fetched size

gb_audio_gb_get_topology() fetches a topology blob of a module-supplied
size, and gbaudio_tplg_parse_data() then walks it by adding the
module-supplied size_dais, size_controls and size_widgets fields to
form the control, widget and route section offsets. Those le32 sizes
are never checked against the fetched blob, so a module reporting a
small topology size but large section sizes makes the offsets point
past the allocation, and parsing reads out of bounds.

Reject a topology whose section sizes do not fit within the fetched
size before it is parsed.


Note You need to log in before you can comment on or make changes to this bug.