CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's ASoC codec driver, specifically in the handling of enumerated controls for the "DEC0 MODE" to "DEC7 MODE" settings. This flaw allows for potential out-of-bounds access due to incorrect data type usage in the control access functions, which could lead to system instability or crashes, particularly in 64-bit kernels with CONFIG_SND_CTL_DEBUG enabled. Organizations utilizing affected Linux systems, especially those relying on audio subsystem functionalities, should prioritize patching to mitigate potential operational disruptions.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: lpass-tx-macro: Fix enum kcontrol accesses The "DEC0 MODE" to "DEC7 MODE" controls are enumerated, but tx_macro_dec_mode_get() and tx_macro_dec_mode_put() access their value through ucontrol->value.integer.value[0] (a long) instead of ucontrol->value.enumerated.item[0] (an unsigned int). This same pattern was fixed in the sibling drivers by commit bcfe5f76cc40 ("ASoC: codecs: rx-macro: fix accessing array out of bounds for enum type") and commit 0ea5eff7c606 ("ASoC: codecs: va-macro: fix accessing array out of bounds for enum type"), but tx-macro was missed. On 64-bit kernels built with CONFIG_SND_CTL_DEBUG, the elem value sanity check catches the 4 bytes written past the enumerated item and every read of these controls fails with -EINVAL: snd-sm8250 sound: control 2:0:0:DEC0 MODE:0: access overflow