CVE-2026-98263 PUBLISHED

ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

ASoC: codecs: rt712-sdca-dmic: fix uninitialized stream_config->type

stream_config is not initialized before being passed to sdw_stream_add_slave(). The type field may contain garbage and is later copied to stream->type by sdw_config_stream().

Zero-initialize stream_config so type defaults to SDW_STREAM_PCM.

While at it, use snd_sdw_params_to_config() helper instead of open-coding the same logic.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 63a511284c9ea72696a5dd0a2d2721bdef19f774 to 6507055733a9d397289277408b52daf422f8a814 (excl.)
  • affected from 63a511284c9ea72696a5dd0a2d2721bdef19f774 to c144447c207e2be24d6ac86d544691ba464caad8 (excl.)
  • affected from 63a511284c9ea72696a5dd0a2d2721bdef19f774 to d93988c9e58d37b677f6ee8aceae741c8d1e30ad (excl.)
  • affected from 63a511284c9ea72696a5dd0a2d2721bdef19f774 to a318ee718e7448cd6bf62d9b3197b6a6a8d4701e (excl.)
  • affected from 63a511284c9ea72696a5dd0a2d2721bdef19f774 to 03a5699a0a04309c597683967aaaf25d1e555ea2 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.4 is affected
  • unaffected from 0 to 6.4 (excl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References