CyberRota Analysis
AI-GeneratedA vulnerability in the Linux kernel's ASoC subsystem allows for potential exploitation through malformed topology data, specifically by improperly validating the size of vendor arrays during parsing. This oversight could lead to buffer overflows or undefined behavior, potentially compromising system integrity or stability. Linux system administrators and developers utilizing the affected kernel versions should prioritize applying the relevant patches to mitigate risks associated with this vulnerability.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: topology: validate vendor array size before parsing sof_parse_token_sets() reads array->size while iterating over topology private data. The loop condition only checks that some data remains, so a malformed topology with a truncated trailing vendor array can make the parser read the size field before a full vendor-array header is available. Validate that the remaining private data contains a complete snd_soc_tplg_vendor_array header before reading array->size. The declared array size check also needs to remain signed. asize is an int, but sizeof(*array) has type size_t, so comparing them directly promotes negative asize values to unsigned and lets them pass the check, as reported in the stable review thread reference below. Cast sizeof(*array) to int when validating the declared array size. This rejects negative, zero and otherwise too-small sizes before the parser dispatches to the tuple-specific code.