CVE-2026-23301
published 2026-03-25CVE-2026-23301: In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Add allocation failure check for Entity name Currently find_sdca_entity_iot()…
PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.11%
1.3th percentile
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: Add allocation failure check for Entity name
Currently find_sdca_entity_iot() can allocate a string for the
Entity name but it doesn't check if that allocation succeeded.
Add the missing NULL check after the allocation.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 6.19.8-1 (forky) | linux 6.19.8-1 (forky) |
| linux | linux | — | — |
| linux | linux | >= 48fa77af2f4a55ab961520f2a0e50560dc0baca8 < bdcc10a86055beb7109a786d94abf5626f375bbd | bdcc10a86055beb7109a786d94abf5626f375bbd |
| linux | linux | >= 48fa77af2f4a55ab961520f2a0e50560dc0baca8 < 27990181031fdcdbe0f7c46011f6404e5d116386 | 27990181031fdcdbe0f7c46011f6404e5d116386 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 6.19.8-1 | 6.19.8-1 |
| linux | linux_kernel | >= 6.19 < 6.19.7 | 6.19.7 |
| linux | linux_kernel | >= 6.19.0 < 6.19.7 | 6.19.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat5.5LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Linux Kernel up to 6.19.6/7.0-rc2 ASoC find_sdca_entity_iot allocation of resources (Nessus ID 303828 / WID-SEC-2026-0861)
vuldb·2026-06-01·CVSS 5.5
CVE-2026-23301 [MEDIUM] Linux Kernel up to 6.19.6/7.0-rc2 ASoC find_sdca_entity_iot allocation of resources (Nessus ID 303828 / WID-SEC-2026-0861)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.19.6/7.0-rc2. The affected element is the function find_sdca_entity_iot of the component ASoC. Executing a manipulation can lead to allocation of resources.
This vulnerability is tracked as CVE-2026-23301. The attack is only possible within the local network. No exploit exists.
The affected component should be upgraded.
OSV
ASoC: SDCA: Add allocation failure check for Entity name
osv·2026-03-25
CVE-2026-23301 ASoC: SDCA: Add allocation failure check for Entity name
ASoC: SDCA: Add allocation failure check for Entity name
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: Add allocation failure check for Entity name
Currently find_sdca_entity_iot() can allocate a string for the
Entity name but it doesn't check if that allocation succeeded.
Add the missing NULL check after the allocation.
OSV
CVE-2026-23301: In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Add allocation failure check for Entity name Currently find_sdca_entit
osv·2026-03-25
CVE-2026-23301 CVE-2026-23301: In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Add allocation failure check for Entity name Currently find_sdca_entit
In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Add allocation failure check for Entity name Currently find_sdca_entity_iot() can allocate a string for the Entity name but it doesn't check if that allocation succeeded. Add the missing NULL check after the allocation.
GHSA
GHSA-hjww-hmp9-xppj: In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: Add allocation failure check for Entity name
Currently find_sdca_ent
ghsa_unreviewed·2026-03-25
CVE-2026-23301 GHSA-hjww-hmp9-xppj: In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: Add allocation failure check for Entity name
Currently find_sdca_ent
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: Add allocation failure check for Entity name
Currently find_sdca_entity_iot() can allocate a string for the
Entity name but it doesn't check if that allocation succeeded.
Add the missing NULL check after the allocation.
Red Hat
kernel: ASoC: SDCA: Add allocation failure check for Entity name
vendor_redhat·2026-03-25·CVSS 5.5
CVE-2026-23301 [LOW] CWE-252 kernel: ASoC: SDCA: Add allocation failure check for Entity name
kernel: ASoC: SDCA: Add allocation failure check for Entity name
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SDCA: Add allocation failure check for Entity name
Currently find_sdca_entity_iot() can allocate a string for the
Entity name but it doesn't check if that allocation succeeded.
Add the missing NULL check after the allocation.
A flaw was found in the Linux kernel's ASoC (Advanced Linux Sound Architecture System on Chip) SDCA (SoundWire Digital Control Adapter) component. The `find_sdca_entity_iot()` function fails to check for successful memory allocation when assigning an entity name. This vulnerability could allow a local attacker to cause a denial of service, leading to system instability or a crash.
Package: kernel (Red Hat Enterprise Linux 10) -
Debian
CVE-2026-23301: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA:...
vendor_debian·2026
CVE-2026-23301 [LOW] CVE-2026-23301: linux - In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA:...
In the Linux kernel, the following vulnerability has been resolved: ASoC: SDCA: Add allocation failure check for Entity name Currently find_sdca_entity_iot() can allocate a string for the Entity name but it doesn't check if that allocation succeeded. Add the missing NULL check after the allocation.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 6.19.8-1)
sid: resolved (fixed in 6.19.8-1)
trixie: resolved
No detection rules found.
No public exploits indexed.
2026-03-25
Published