PT-2026-36411 · Linux · Linux Kernel

Published

2026-05-01

·

Updated

2026-05-01

·

CVE-2026-31776

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the ALSA ctxfi component, the daio device index() function fails to properly handle the SPDIF1 DAIO type for hw20k2. This causes the function to return -EINVAL, leading to an out-of-bounds array access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Validation of Array Index

Weakness Enumeration

Related Identifiers

CVE-2026-31776
ECHO-C7D3-9907-5FB9

Affected Products

Linux Kernel