In the Linux kernel, the following vulnerability has been resolved:
ASoC: codecs: tx-macro: Fix for KASAN: slab-out-of-bounds
When we run syzkaller we get below Out of Bound. "KASAN: slab-out-of-bounds Read in regcache_flat_read"
Below is the backtrace of the issue:
dump_backtrace+0x0/0x4c8 show_stack+0x34/0x44 dump_stack_lvl+0xd8/0x118 print_address_description+0x30/0x2d8 kasan_report+0x158/0x198 __asan_report_load4_noabort+0x44/0x50 regcache_flat_read+0x10c/0x110 regcache_read+0xf4/0x180 _regmap_read+0xc4/0x278 _regmap_update_bits+0x130/0x290 regmap_update_bits_base+0xc0/0x15c snd_soc_component_update_bits+0xa8/0x22c snd_soc_component_write_field+0x68/0xd4 tx_macro_digital_mute+0xec/0x140
Actually There is no need to have decimator with 32 bits. By limiting the variable with short type u8 issue is resolved.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 30, 2025 |
| Ubuntu | — | Upgrade linux-gcp-5.15Upgrade linux-nvidiaUpgrade linux-ibmUpgrade linux-raspiUpgrade linux-lowlatencyUpgrade linux-nvidia-tegraUpgrade linux-riscv-5.15Upgrade linux-oracleUpgrade linux-azure-fde-5.15Upgrade linux-gkeopUpgrade linux-oracle-5.15Upgrade linux-xilinx-zynqmpUpgrade linux-gcpUpgrade linux-aws-5.15Upgrade linux-gkeUpgrade linux-ibm-5.15Upgrade linux-nvidia-tegra-5.15Upgrade linux-realtimeUpgrade linux-azure-5.15Upgrade linux-intel-iot-realtimeUpgrade linux-intel-iotgUpgrade linux-kvmUpgrade linux-hwe-5.15Upgrade linux-nvidia-tegra-igxUpgrade linux-bluefieldUpgrade linux-intel-iotg-5.15Upgrade linuxUpgrade linux-azureUpgrade linux-lowlatency-hwe-5.15Upgrade linux-aws | Jan 6, 2026 | Jan 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub