Vulnerability record · CVE-2026-72303 · published 15 August 2026
CVE-2026-72303: In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Validate notific…
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Validate notification payload size Validate MODULE_NOTIFICATION payload length before reading bytes/channel data in control update handling.
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-control: Validate notification payload size Validate MODULE_NOTIFICATION payload length before reading bytes/channel data in control update handling.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Track CVE-2026-72303 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2026-72303), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.