Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-72300

Published Aug 15, 2026 EPSS 0.20% (10th pctl)

Overview

CVE-2026-72300 is a known-severity vulnerability. It was published on August 15, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ASoC: SOF: topology: validate vendor array size before parsing

sof_parse_token_sets() reads array->size while iterating over topology

private data. The loop condition only checks that some data remains, so a

malformed topology with a truncated trailing vendor array can make the

parser read the size field before a full vendor-array header is available.

Validate that the remaining private data contains a complete

snd_soc_tplg_vendor_array header before reading array->size.

The declared array size check also needs to remain signed. asize is an int,

but sizeof(*array) has type size_t, so comparing them directly promotes

negative asize values to unsigned and lets them pass the check,

as reported in the stable review thread reference below.

Cast sizeof(*array) to int when validating the declared array size. This

rejects negative, zero and otherwise too-small sizes before the parser

dispatches to the tuple-specific code.

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-72300?

CVE-2026-72300 is a known-severity vulnerability. It was published on August 15, 2026.

How severe is CVE-2026-72300?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-72300?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-72300?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-72300 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.