CVE-2026-53350 Details
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: wm_adsp: Fix NULL dereference when removing firmware controls In wm_adsp_control_remove() check that the priv pointer is not NULL before attempting to cleanup what it points to. When cs_dsp creates a control it calls wm_adsp_control_add_cb() so that wm_adsp can create its own private control data. There are two cases where private data is not created: 1. The control is a SYSTEM control, so an ALSA control is not created. 2. The codec driver has registered a control_add() callback that hides the control, so wm_adsp_control_add() is not called. When cs_dsp_remove destroys its control list it calls wm_adsp_control_remove() for each control. But wm_adsp_control_remove() was attempting to cleanup the private data pointed to by cs_ctl->priv without checking the pointer for NULL.
A NULL pointer dereference vulnerability has been identified in the Linux kernel's ASoC WM_ADSP component. This issue arises in the 'wm_adsp_control_remove()' function, where the code attempts to clean up private data without first verifying that the pointer is not NULL. The vulnerability can occur when 'cs_dsp' creates a control that is either a SYSTEM control, which does not generate an ALSA control, or when a codec driver registers a control_add() callback that conceals the control, preventing 'wm_adsp_control_add()' from being called. As a result, when 'cs_dsp_remove' deletes its control list and invokes 'wm_adsp_control_remove()' for each control, the absence of a NULL check leads to a dereference of a NULL pointer, causing a crash.
The vulnerability has been addressed in the Linux kernel. Users should upgrade to the latest version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/10def23b67b42679d5b1a356e1a6f3498bd188c3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/12e579b889624ec54a201d98fdff975de556c731 | kernel.org | Patch |
| https://git.kernel.org/stable/c/2f1be283aa777d655525d000d16474b7e7d015ea | kernel.org | Patch |
| https://git.kernel.org/stable/c/5ee9bbe2af2f373e08d3017f9aef2f2eaf29fbc3 | kernel.org | Patch |
| https://git.kernel.org/stable/c/6effd6f7b0ba1f5d1df702b2ef7460bcc215e9b7 | kernel.org | Patch |
| https://git.kernel.org/stable/c/7d3fb78b550301e43fdc60312aed733069694426 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.16, < 6.1.176 >= 6.2, < 6.6.143 >= 6.7, < 6.12.94 >= 6.13, < 6.18.36 >= 6.19, < 7.0.13 7.1 rc1 7.1 rc2 7.1 rc3 7.1 rc4 7.1 rc5 7.1 rc6 7.1 rc7 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | Initial Analysis | [email protected] |
| Jul 1, 2026 | New CVE Received | kernel.org |