news.mlab.sh
Vulnerabilities
Vulnerability

CVE-2026-46088

Reference data from vuln.mlab.sh, coverage from our own index.

CVSS
5.5 Medium
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Risk score
44.0
Published
2026-05-27
Status
Published

In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_names() snd_ctl_elem_init_enum_names() advances pointer p through the names buffer while decrementing buf_len. If buf_len reaches zero but items remain, the next iteration calls strnlen(p, 0). While strnlen(p, 0) returns 0 and would hit the existing name_len == 0 error path, CONFIG_FORTIFY_SOURCE's fortified strnlen() first checks maxlen against __builtin_dynamic_object_size(). When Clang loses track of p's object size inside the loop, this triggers a BRK exception panic before the return value is examined. Add a buf_len == 0 guard at the loop entry to prevent calling fortified strnlen() on an exhausted buffer. Found by kernel fuzz testing through Xiaomi Smartphone. A flaw was found in the Linux kernel's Advanced Linux Sound Architecture (ALSA) control component. Improper validation of the buffer length before a string length operation in the `snd_ctl_elem_init_enum_names()` function can lead to a system panic. This vulnerability could allow a local attacker to trigger a Denial of Service (DoS), making the system unresponsive.

Weaknesses

CWE-805

Coverage 7

Advisories and references