CVE-2026-31776

HIGH

ALSA: ctxfi: Fix missing SPDIFI1 index handling

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: ctxfi: Fix missing SPDIFI1 index handling SPDIF1 DAIO type isn't properly handled in daio_device_index() for hw20k2, and it returned -EINVAL, which ended up with the out-of-bounds array access. Follow the hw20k1 pattern and return the proper index for this type, too.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-129
Status published
Products (22)
Linux/Linux < 6.19
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 28222e13666b5d26bf66563c056069ed32f87b33
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 57698f184e1afbe054b3cd30e2c43a67c11d7f5e
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 5b39985303a639b159dea306a032c08ef22f029d
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 950decf59d4e978b60a792ce0b3e1555a608f489
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - a0b45bdfffce9894b39392d061c14fda24de8b67
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - a3b0e5f84058a9c3d0542a71c2b3a7801e4ee26a
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - b045ab3dff97edae6d538eeff900a34c098761f8
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - c8859675f1cf92fe2eb25ef525440702140a0b55
Linux/Linux 5.10.253 - 5.10.*
... and 12 more
Published May 01, 2026
Tracked Since May 01, 2026