SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-80581

UNKNOWN · CVSS N/A EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-20

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's ASoC (ALSA System on Chip) component, specifically in the IPC4 PCM interface, where it improperly handles IPC timeouts and firmware crashes. This can lead to state inconsistencies in the audio processing pipeline, potentially causing system instability or degraded performance during audio operations. Linux distributions utilizing the affected kernel versions should prioritize this issue to ensure reliable audio functionality and system stability.

CVE
CVE-2026-80581
Severity
UNKNOWN
CVSS
N/A
EPSS
0.16%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout Ignore IPC errors for pipeline state change if the firmware state is crashed or the IPC has timed out. If the firmware has crashed the kernel still needs to go through the state changes to reset its internal to be able to correctly work the next time the DSP is booted up. The case with IPC timeout is a bit more problematic, but it has been rootcaused to be the result of system scheduling blockage and the firmware did actually received and handled the message, but the reply handling got blocked by issues outside of the SOF stack. So far the best way to handle this is to continue with setting the state.