CVE-2026-43443

MEDIUM

ASoC: amd: acp-mach-common: Add missing error check for clock acquisition

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp-mach-common: Add missing error check for clock acquisition The acp_card_rt5682_init() and acp_card_rt5682s_init() functions did not check the return values of clk_get(). This could lead to a kernel crash when the invalid pointers are later dereferenced by clock core functions. Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding IS_ERR() checks immediately after each clock acquisition.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 3.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-476
Status published
Products (8)
Linux/Linux < 5.16
Linux/Linux 5.16
Linux/Linux 6.19.9 - 6.19.*
Linux/Linux 7.0
Linux/Linux d4c750f2c7d44b5b39e197308bc3f510205bba4b - 0cee68fb7f4cf1562e067c5a82d25062a973b0d0
Linux/Linux d4c750f2c7d44b5b39e197308bc3f510205bba4b - 30c64fb9839949f085c8eb55b979cbd8a4c51f00
linux/linux_kernel 7.0 rc1 (3 CPE variants)
linux/linux_kernel 5.16 - 6.19.9
Published May 08, 2026
Tracked Since May 08, 2026