CVE-2026-43480
In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function did not check the return value of clk_get(), which could lead to…
Does this matter?
Lower severity and a low EPSS score (0.11%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function did not check the return value of clk_get(), which could lead to dereferencing error pointers in rt5682_clk_enable(). Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding proper IS_ERR() checks for both clock acquisitions.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.11% probability · 2th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/092522621901b5e6af61db04a53f5b313903c6d0Patch
- https://git.kernel.org/stable/c/2b0c4a399c8d27f20ecf17dda76751141d6dbb59Patch
- https://git.kernel.org/stable/c/2dc43ac8da7b2bebc5a51a3d86a6275d78f27cffPatch
- https://git.kernel.org/stable/c/33de168afdd57265a0e0c20dbd3648a2d8f7cdc4Patch
- https://git.kernel.org/stable/c/35c7624d30cb45ec336cd16ce072acc32ae351cbPatch
- https://git.kernel.org/stable/c/4d802f23fcbfec05134653fd001f6c7c3fd55196Patch
- https://git.kernel.org/stable/c/53f3a900e9a383d47af7253076e19f510c5708d0Patch
- https://git.kernel.org/stable/c/790851ecc983c719fa2e6adb17b02f3acc1d217dPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.