CVE-2026-43480
📛 CVE Title
ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition
Description
In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function did not check the return value of clk_get(), which could lead to dereferencing error pointers in rt5682_clk_enable(). Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding proper IS_ERR() checks for both clock acquisitions.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Linux
- CVSS severity
- medium
- CVSS score
- 5.5 / 10
- CVSS vector
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- Effective score
- 5.5 / 10 MEDIUM source: CNA overview
- CWE(s)
- —
- Reserved
- 2026-05-01
- Published
- 2026-05-13 17:08 UTC
- Last updated
- 2026-05-13 17:08 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/43xxx/CVE-2026-43480.json
- Linked Threat
- CVE-2026-43480 — CVE-2026-43480
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2026-05-13 16:16:51 UTC
- NVD last modified
- 2026-05-13 16:16:51 UTC
- EPSS score
- 0.0003 (probability of exploitation in next 30 days)
- EPSS percentile
- 9.59% vs all CVEs — higher = more likely to be exploited, as of 2026-05-24
NVD / KEV / EPSS data refreshed 2026-05-25 08:51 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2026-30016 - Assigner
- Linux
- Published
- May 13, 2026, 3:08:28 PM
- Updated
- May 13, 2026, 3:08:28 PM
- EUVD base score
- 0.0 / 10
- EUVD-reported EPSS
- 0.0300
- Vendors
- Linux
- Products
-
Linux (patch: 0)Linux (6b8e4e7db3cd236a2cbb720360fb135087a2ac1d <35c7624d30cb45ec336cd16ce072acc32ae351cb)Linux (6b8e4e7db3cd236a2cbb720360fb135087a2ac1d <2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff)Linux (patch: 6.12.78)Linux (patch: 6.1.167)Linux (6b8e4e7db3cd236a2cbb720360fb135087a2ac1d <4d802f23fcbfec05134653fd001f6c7c3fd55196)Linux (patch: 5.10.253)Linux (6b8e4e7db3cd236a2cbb720360fb135087a2ac1d <790851ecc983c719fa2e6adb17b02f3acc1d217d)Linux (6b8e4e7db3cd236a2cbb720360fb135087a2ac1d <092522621901b5e6af61db04a53f5b313903c6d0)Linux (patch: 6.18.19)Linux (5.7)Linux (6b8e4e7db3cd236a2cbb720360fb135087a2ac1d <53f3a900e9a383d47af7253076e19f510c5708d0)Linux (6b8e4e7db3cd236a2cbb720360fb135087a2ac1d <33de168afdd57265a0e0c20dbd3648a2d8f7cdc4)Linux (patch: 7.0)Linux (patch: 6.19.9)Linux (patch: 6.6.130)Linux (6b8e4e7db3cd236a2cbb720360fb135087a2ac1d <2b0c4a399c8d27f20ecf17dda76751141d6dbb59)Linux (patch: 5.15.203)
ENISA description: In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition The acp3x_5682_init() function did not check the return value of clk_get(), which could lead to dereferencing error pointers in rt5682_clk_enable(). Fix this by: 1. Changing clk_get() to the device-managed devm_clk_get(). 2. Adding proper IS_ERR() checks for both clock acquisitions.
EUVD references (8)
- https://git.kernel.org/stable/c/2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff
- https://git.kernel.org/stable/c/4d802f23fcbfec05134653fd001f6c7c3fd55196
- https://git.kernel.org/stable/c/2b0c4a399c8d27f20ecf17dda76751141d6dbb59
- https://git.kernel.org/stable/c/35c7624d30cb45ec336cd16ce072acc32ae351cb
- https://git.kernel.org/stable/c/33de168afdd57265a0e0c20dbd3648a2d8f7cdc4
- https://git.kernel.org/stable/c/790851ecc983c719fa2e6adb17b02f3acc1d217d
- https://git.kernel.org/stable/c/092522621901b5e6af61db04a53f5b313903c6d0
- https://git.kernel.org/stable/c/53f3a900e9a383d47af7253076e19f510c5708d0
Affected products (2)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Linux | Linux |
6b8e4e7db3cd236a2cbb720360fb135087a2ac1d (affected),
6b8e4e7db3cd236a2cbb720360fb135087a2ac1d (affected),
6b8e4e7db3cd236a2cbb720360fb135087a2ac1d (affected),
6b8e4e7db3cd236a2cbb720360fb135087a2ac1d (affected),
6b8e4e7db3cd236a2cbb720360fb135087a2ac1d (affected),
6b8e4e7db3cd236a2cbb720360fb135087a2ac1d (affected),
6b8e4e7db3cd236a2cbb720360fb135087a2ac1d (affected),
6b8e4e7db3cd236a2cbb720360fb135087a2ac1d (affected)
|
— |
| Linux | Linux |
5.7 (affected),
0 (unaffected),
5.10.253 (unaffected),
5.15.203 (unaffected),
6.1.167 (unaffected),
6.6.130 (unaffected),
6.12.78 (unaffected),
6.18.19 (unaffected),
6.19.9 (unaffected),
7.0 (unaffected)
|
— |
Vendor references (8)
References embedded in the original CVE record by the assigning CNA.
- https://git.kernel.org/stable/c/2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff
- https://git.kernel.org/stable/c/4d802f23fcbfec05134653fd001f6c7c3fd55196
- https://git.kernel.org/stable/c/2b0c4a399c8d27f20ecf17dda76751141d6dbb59
- https://git.kernel.org/stable/c/35c7624d30cb45ec336cd16ce072acc32ae351cb
- https://git.kernel.org/stable/c/33de168afdd57265a0e0c20dbd3648a2d8f7cdc4
- https://git.kernel.org/stable/c/790851ecc983c719fa2e6adb17b02f3acc1d217d
- https://git.kernel.org/stable/c/092522621901b5e6af61db04a53f5b313903c6d0
- https://git.kernel.org/stable/c/53f3a900e9a383d47af7253076e19f510c5708d0
MITRE references (8) cveawg.mitre.org
Pulled from MITRE's CVE Services API by the 🛰 Backfill from MITRE button.
- https://git.kernel.org/stable/c/33de168afdd57265a0e0c20dbd3648a2d8f7cdc4
- https://git.kernel.org/stable/c/35c7624d30cb45ec336cd16ce072acc32ae351cb
- https://git.kernel.org/stable/c/4d802f23fcbfec05134653fd001f6c7c3fd55196
- https://git.kernel.org/stable/c/53f3a900e9a383d47af7253076e19f510c5708d0
- https://git.kernel.org/stable/c/790851ecc983c719fa2e6adb17b02f3acc1d217d
- https://git.kernel.org/stable/c/092522621901b5e6af61db04a53f5b313903c6d0
- https://git.kernel.org/stable/c/2b0c4a399c8d27f20ecf17dda76751141d6dbb59
- https://git.kernel.org/stable/c/2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- https://attackerkb.com/topics/CVE-2026-43480 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-30016 rapid7:euvd.enisa.europa.eu
- https://www.first.org/epss/ tenable:www.first.org
- https://nvd.nist.gov/vuln/detail/CVE-2026-43480 tenable:nvd.nist.gov
- https://www.cve.org/CVERecord?id=CVE-2026-43480 tenable:www.cve.org
NVD-tagged references (8)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
- https://git.kernel.org/stable/c/092522621901b5e6af61db04a53f5b313903c6d0 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- https://git.kernel.org/stable/c/2b0c4a399c8d27f20ecf17dda76751141d6dbb59 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- https://git.kernel.org/stable/c/2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- https://git.kernel.org/stable/c/33de168afdd57265a0e0c20dbd3648a2d8f7cdc4 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- https://git.kernel.org/stable/c/35c7624d30cb45ec336cd16ce072acc32ae351cb 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- https://git.kernel.org/stable/c/4d802f23fcbfec05134653fd001f6c7c3fd55196 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- https://git.kernel.org/stable/c/53f3a900e9a383d47af7253076e19f510c5708d0 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- https://git.kernel.org/stable/c/790851ecc983c719fa2e6adb17b02f3acc1d217d 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Remediations (18)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:blogs.oracle.com
For more information about the Critical Patch Update program, see the security vulnerability remediation practices page located on the Oracle Trust Center.
2026-05-23 20:55 UTC -
web:blogs.oracle.com
As a follow-up to our recent post, Accelerating Vulnerability Detection and Response, Oracle is announcing the start date and cadence for monthly Critical Security Patch Updates (CSPUs). Beginning May 28, 2026 , Oracle will deliver a Critical Security Patch Update (CSPU) each month.
2026-05-23 20:55 UTC -
web:cyberpress.org
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two actively exploited Microsoft Defender vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, issuing an urgent remediation directive for federal agencies with a due date of June 3, 2026 .
2026-05-23 20:55 UTC -
web:krebsonsecurity.com
Microsoft expects that exploitation is more likely. May's Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.
2026-05-23 20:55 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-23 20:55 UTC -
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-05-23 20:55 UTC -
web:www.bleepingcomputer.com
Today is Microsoft's April 2026 Patch Tuesday with security updates for 167 flaws, including 2 zero-day vulnerabilities.
2026-05-23 20:55 UTC -
web:www.crowdstrike.com
Microsoft's April 2026 Patch Tuesday addresses 164 CVEs , featuring 8 Critical vulnerabilities, one exploited zero-day, and one disclosed zero-day.
2026-05-23 20:55 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-23 20:55 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-23 20:55 UTC -
web:builtin.com
Log4j Vulnerability Explained: What It Is and How to Fix It The Log4j vulnerability is a software vulnerability in Log4j — an open-source library commonly used in Java-based systems and applications. Here's how the vulnerability works, the response to and impact of the vulnerability and tips to mitigate it.
2026-06-03 22:32 UTC -
web:cybersecuritynews.com
Microsoft's May 2026 Patch Tuesday lands with a heavy enterprise focus, fixing 120 vulnerabilities across Windows, Office, Azure, developer tools, and Microsoft 365 apps, including 29 remote code execution (RCE) flaws rated Critical.
2026-06-03 22:32 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-06-03 22:32 UTC -
web:securityvulnerability.io
Explore the XML Layout vulnerability in Apache Log4j Core affecting versions up to 2.25.3, including mitigation steps for CVE - 2026 -34480.
2026-06-03 22:32 UTC -
web:www.cisecurity.org
<p>Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or ...
2026-06-03 22:32 UTC -
web:www.cve.news
If you use Apache Log4j 2's XmlLayout to produce XML logs, there's a good chance your log files may not be as reliable as you think. CVE - 2026 -34480 reveals a subtle but critical bug in Log4j Core versions up to and including 2.25.3: it fails to sanitize characters
2026-06-03 22:32 UTC -
web:www.herodevs.com
Apache Log4j 2 (≤2.25.3) vulnerability ( CVE - 2026 -34480) allows invalid XML characters in XmlLayout output, causing log parsing failures or dropped records, leading to potential denial of service; fixed in 2.25.4.
2026-06-03 22:32 UTC -
web:www.sentinelone.com
CVE - 2026 -34480 is an XXE vulnerability in Apache Log4j Core XmlLayout. Learn about its impact, affected versions, and mitigation methods.
2026-06-03 22:32 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2026-43480.json.
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"sound/soc/amd/acp3x-rt5682-max9836.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff",
"status": "affected",
"version": "6b8e4e7db3cd236a2cbb720360fb135087a2ac1d",
"versionType": "git"
},
{
"lessThan": "4d802f23fcbfec05134653fd001f6c7c3fd55196",
"status": "affected",
"version": "6b8e4e7db3cd236a2cbb720360fb135087a2ac1d",
"versionType": "git"
},
{
"lessThan": "2b0c4a399c8d27f20ecf17dda76751141d6dbb59",
"status": "affected",
"version": "6b8e4e7db3cd236a2cbb720360fb135087a2ac1d",
"versionType": "git"
},
{
"lessThan": "35c7624d30cb45ec336cd16ce072acc32ae351cb",
"status": "affected",
"version": "6b8e4e7db3cd236a2cbb720360fb135087a2ac1d",
"versionType": "git"
},
{
"lessThan": "33de168afdd57265a0e0c20dbd3648a2d8f7cdc4",
"status": "affected",
"version": "6b8e4e7db3cd236a2cbb720360fb135087a2ac1d",
"versionType": "git"
},
{
"lessThan": "790851ecc983c719fa2e6adb17b02f3acc1d217d",
"status": "affected",
"version": "6b8e4e7db3cd236a2cbb720360fb135087a2ac1d",
"versionType": "git"
},
{
"lessThan": "092522621901b5e6af61db04a53f5b313903c6d0",
"status": "affected",
"version": "6b8e4e7db3cd236a2cbb720360fb135087a2ac1d",
"versionType": "git"
},
{
"lessThan": "53f3a900e9a383d47af7253076e19f510c5708d0",
"status": "affected",
"version": "6b8e4e7db3cd236a2cbb720360fb135087a2ac1d",
"versionType": "git"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"sound/soc/amd/acp3x-rt5682-max9836.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "5.7"
},
{
"lessThan": "5.7",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.253",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.203",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.167",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.130",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.78",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.19",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.19.*",
"status": "unaffected",
"version": "6.19.9",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.0",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.253",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.203",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.167",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.130",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.78",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.19",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.19.9",
"versionStartIncluding": "5.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.0",
"versionStartIncluding": "5.7",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition\n\nThe acp3x_5682_init() function did not check the return value of\nclk_get(), which could lead to dereferencing error pointers in\nrt5682_clk_enable().\n\nFix this by:\n1. Changing clk_get() to the device-managed devm_clk_get().\n2. Adding proper IS_ERR() checks for both clock acquisitions."
}
],
"providerMetadata": {
"dateUpdated": "2026-05-13T15:08:28.517Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/2dc43ac8da7b2bebc5a51a3d86a6275d78f27cff"
},
{
"url": "https://git.kernel.org/stable/c/4d802f23fcbfec05134653fd001f6c7c3fd55196"
},
{
"url": "https://git.kernel.org/stable/c/2b0c4a399c8d27f20ecf17dda76751141d6dbb59"
},
{
"url": "https://git.kernel.org/stable/c/35c7624d30cb45ec336cd16ce072acc32ae351cb"
},
{
"url": "https://git.kernel.org/stable/c/33de168afdd57265a0e0c20dbd3648a2d8f7cdc4"
},
{
"url": "https://git.kernel.org/stable/c/790851ecc983c719fa2e6adb17b02f3acc1d217d"
},
{
"url": "https://git.kernel.org/stable/c/092522621901b5e6af61db04a53f5b313903c6d0"
},
{
"url": "https://git.kernel.org/stable/c/53f3a900e9a383d47af7253076e19f510c5708d0"
}
],
"title": "ASoC: amd: acp3x-rt5682-max9836: Add missing error check for clock acquisition",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-43480",
"datePublished": "2026-05-13T15:08:28.517Z",
"dateReserved": "2026-05-01T14:12:56.012Z",
"dateUpdated": "2026-05-13T15:08:28.517Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}