CVE-2026-80581

In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout Ignore IPC errors for pipeline state change if the firmware state is crashed or the IPC has timed out. If the firmware has crashed the kernel still needs to go through the state changes to reset its internal to be able to correctly work the next time the DSP is booted up. The case with IPC timeout is a bit more problematic, but it has been rootcaused to be the result of system scheduling blockage and the firmware did actually received and handled the message, but the reply handling got blocked by issues outside of the SOF stack. So far the best way to handle this is to continue with setting the state.

Package Linux Kernel
Published 2026-08-26
Last modified 2026-08-26
Patch available
Yes

Affected versions

Linux kernel versions 6.6.23, 6.7.11, 6.8 and later are affected. Fixed in 6.6.154, 6.18.46, 7.1.10, 7.2 and their respective stable series.

Affected from
≥ 6.6.23 ≥ 6.7.11 ≥ 6.8
Fixed in
✓ 6.6.154 6.6.x ✓ 6.18.46 6.18.x ✓ 7.1.10 7.1.x ✓ 7.2

Frequently asked questions

  • What is CVE-2026-80581?

    CVE-2026-80581 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.6.23 onward and has been patched in 6.6.154, 6.18.46, 7.1.10 and others. CVE-2026-80581 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.

  • Is there a patch available for CVE-2026-80581?

    Yes. CVE-2026-80581 has been patched. Fixed versions include 6.6.154, 6.18.46, 7.1.10 and others. If you are running Linux kernel 6.6.23 or later up to the fix versions, apply the relevant patch for your kernel branch.

  • Is CVE-2026-80581 actively exploited?

    No. CVE-2026-80581 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.