SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-74295

HIGH · CVSS 7.1 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-15 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's ASoC HDAC HDMI driver, specifically in the hdac_hdmi_set_pin_port_mux() function, which improperly validates enum values before indexing an array. This flaw could allow an attacker to exploit out-of-range values, potentially leading to memory access violations. Organizations using affected Linux systems should prioritize patching this vulnerability to mitigate risks associated with driver exploitation.

CVE
CVE-2026-74295
Severity
HIGH
CVSS
7.1
EPSS
0.13%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: hdac_hdmi: Validate written enum value hdac_hdmi_set_pin_port_mux() uses the written enum value to index the texts array before calling snd_soc_dapm_put_enum_double(), which validates that the value is within the enum item range. An out-of-range value can therefore make the driver read past the texts array before the helper rejects the write. Move the lookup after the helper has accepted the value.