← All Advisories

CVE-2026-74291

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-74291

Key Details

CVECVE-2026-74291
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

ASoC: topology: Check PCM and DAI name strings before use

Topology objects store several PCM and DAI names in fixed-size UAPI

arrays. Other topology parser paths validate these fields with bounded

strnlen() checks before using them as C strings, but the PCM and DAI

paths still pass some fixed-size arrays directly to strlen(),

devm_kstrdup(), DAI lookup, and diagnostic prints.

A malformed topology blob with a non-NUL-terminated PCM, DAI, or stream

capability name can therefore make the parser read past the end of the

fixed-size field.

Reject unterminated PCM and DAI name fields before consuming them as C

strings. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-74291
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-74291