---
id: CVE-2026-93280
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  greybus: audio: bound the topology section sizes against the fetched size

  gb_audio_gb_get_topology() fetches a topology blob of a module-supplied
  size, and gbaudio_tpl…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  greybus: audio: bound the topology section sizes against the fetched size

  gb_audio_gb_get_topology() fetches a topology blob of a module-supplied
  size, and gbaudio_tpl…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 184992e305f1de3a3d5fa446da3a2bc76be7c54a <
    ba86de9f7b0d7903d2df5ea2373e34d8ca3fc43e
  - >-
    Linux >= 184992e305f1de3a3d5fa446da3a2bc76be7c54a <
    dd5593aee0a0fb353e1164aff7b65e563fe1f232
  - >-
    Linux >= 184992e305f1de3a3d5fa446da3a2bc76be7c54a <
    6f764363b3173d805be11e59a8f23ecee2d420d5
  - >-
    Linux >= 184992e305f1de3a3d5fa446da3a2bc76be7c54a <
    52daf9de692ebac813d110eb1e677dc0e1f4a5ab
  - >-
    Linux >= 184992e305f1de3a3d5fa446da3a2bc76be7c54a <
    d0f6eaba60705bacd9bb4ce48eab50ef3f546777
  - >-
    Linux >= 184992e305f1de3a3d5fa446da3a2bc76be7c54a <
    c9191f2e2f35f1209eb2dc24b31129dd47b48c16
  - >-
    Linux >= 184992e305f1de3a3d5fa446da3a2bc76be7c54a <
    cfcc5a41a9664eb68023aae4cd0d485b256bd7c7
  - >-
    Linux >= 184992e305f1de3a3d5fa446da3a2bc76be7c54a <
    33d8c7b794d2a30637c9d3fcb478f1d3222bef1e
  - Linux 4.9
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T05:17:01.627'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-93280'
references:
  - url: 'https://git.kernel.org/stable/c/33d8c7b794d2a30637c9d3fcb478f1d3222bef1e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/52daf9de692ebac813d110eb1e677dc0e1f4a5ab'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/6f764363b3173d805be11e59a8f23ecee2d420d5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ba86de9f7b0d7903d2df5ea2373e34d8ca3fc43e'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/c9191f2e2f35f1209eb2dc24b31129dd47b48c16'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cfcc5a41a9664eb68023aae4cd0d485b256bd7c7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d0f6eaba60705bacd9bb4ce48eab50ef3f546777'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/dd5593aee0a0fb353e1164aff7b65e563fe1f232'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-24T16:47:15.842Z'
epss: 0.00321
epssPercentile: 0.22502
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

greybus: audio: bound the topology section sizes against the fetched size

gb_audio_gb_get_topology() fetches a topology blob of a module-supplied
size, and gbaudio_tplg_parse_data() then walks it by adding the
module-supplied size_dais, size_controls and size_widgets fields to
form the control, widget and route section offsets. Those le32 sizes
are never checked against the fetched blob, so a module reporting a
small topology size but large section sizes makes the offsets point
past the allocation, and parsing reads out of bounds.

Reject a topology whose section sizes do not fit within the fetched
size before it is parsed.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
