CVE-2026-80526: Linux
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ASoC: tas2562: Validate values for volume writes tas2562_volume_control_put() does not do any validation of the control value written by userspace, it uses it to look up a value in a fixed size array which can easily be overflowed and then writes whatever value it gets back to the device. Add validation that we are loading a value we have in the array.
Affected products
- Linux Linux: from 5.7, before 6.6.153 (fixed in 6.6.153); from 6.7, before 6.12.105 (fixed in 6.12.105); from 6.13, before 6.18.46 (fixed in 6.18.46); from 6.19, before 7.1.10 (fixed in 7.1.10)
Published 2026-08-26. Last modified 2026-08-27.