{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  ASoC: Intel: avs: Refactor and fix init_config access  Existing code accesses enties found in -\u003einit_configs array through indexes that are part of -\u003econfig_ids array.  Those two are limited by: -\u003enum_init_configs and -\u003enum_config_ids respectively.  Using ID larger or equal to -\u003enum_init_configs leads to out-of-bounds access:  avs_path_module_send_init_configs() loop: \t(...) \u0026acomp-\u003etplg-\u003einit_configs[ids[i]] \t\t\t\t\t^ out-of-bounds candidate  Rather than adding another if-statement, refactor the code.  There is no need to store the IDs, have a list of pointers to actual config-entries instead.  As the verification of -\u003einit_config entries does not differ from verification of other types that are part of the topology.c file, simply reuse the code.",
  "id": "DEBIAN-CVE-2026-98053",
  "modified": "2026-09-26T04:47:38.982356818Z",
  "published": "2026-09-25T11:17:34.227Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-98053"
    }
  ],
  "upstream": [
    "CVE-2026-98053"
  ]
}