CVE-2026-80911

    Dashboard / Vulnerabilities / CVE-2026-80911

    CVE-2026-80911

    Published: 4 Sept 2026Last Modified: 6 Sept 2026

    Summary: ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked()

    Details: In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() If either tplg_ops->dai_config or widget_kcontrol_setup fail during widget setup we would double decrement the use_count of the widget because the sof_widget_free_unlocked() would be called twice, similarly the core_put would be invoked twice as well. Since the use_count and core_put() is handled within the widget_free function we need to return without falling through the pipe_widget_free label. The fixes tag is picked to the last change around this part of the code which is adequately old enough for backporting purposes.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 3c124f09b7ff0434b076a8dec1ed446a6170b549

    Affected versions

    v6.6.152
    v6.6.151
    v6.6.150
    v6.6.149
    v6.6.148
    v6.6.147
    v6.6.146
    v6.6.145
    v6.6.144
    v6.6.143
    v6.6.142
    v6.6.141
    v6.6.140
    v6.6.139
    v6.6.138
    v6.6.137
    v6.6.136
    v6.6.135
    v6.6.134
    v6.6.133
    v6.6.132
    v6.6.131
    v6.6.130
    v6.6.129
    v6.6.128
    v6.6.127
    v6.6.126
    v6.6.125
    v6.6.124
    v6.6.123
    v6.6.122
    v6.6.121
    v6.6.120
    v6.6.119
    v6.6.118
    v6.6.117
    v6.6.116
    v6.6.115
    v6.6.114
    v6.6.113
    v6.6.112
    v6.6.111
    v6.6.110
    v6.6.109
    v6.6.108
    v6.6.107
    v6.6.106
    v6.6.105
    v6.6.104
    v6.6.103
    v6.6.102
    v6.6.101
    v6.6.100
    v6.6.99
    v6.6.98
    v6.6.97
    v6.6.96
    v6.6.95
    v6.6.94
    v6.6.93
    v6.6.92
    v6.6.91
    v6.6.90
    v6.6.89
    v6.6.88
    v6.6.87
    v6.6.86
    v6.6.85
    v6.6.84
    v6.6.83
    v6.6.82
    v6.6.81
    v6.6.80
    v6.6.79
    v6.6.78
    v6.6.77
    v6.6.76
    v6.6.75
    v6.6.74
    v6.6.73
    v6.6.72
    v6.6.71
    v6.6.70
    v6.6.69
    v6.6.68
    v6.6.67
    v6.6.66
    v6.6.65
    v6.6.64
    v6.6.63
    v6.6.62
    v6.6.61
    v6.6.60
    v6.6.59
    v6.6.58
    v6.6.57
    v6.6.56
    v6.6.55
    v6.6.54
    v6.6.53
    v6.6.52
    v6.6.51
    v6.6.50
    v6.6.49
    v6.6.48
    v6.6.47
    v6.6.46
    v6.6.45
    v6.6.44
    v6.6.43
    v6.6.42
    v6.6.41
    v6.6.40
    v6.6.39
    v6.6.38
    v6.6.37
    v6.6.36
    v6.6.35
    v6.6.34
    v6.6.33
    v6.6.32
    v6.6.31
    v6.6.30
    v6.6.29
    v6.6.28
    v6.6.27
    v6.6.26
    v6.6.25
    v6.6.24
    v6.6.23
    v6.6.22
    v6.6.21
    v6.6.20
    v6.6.19
    v6.6.18
    v6.6.17
    v6.6.16
    v6.6.15
    v6.6.14
    v6.6.13

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-80911 | CVE-DB