CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-80581

lowCVSS 3.3covered by 2 sourcesfirst seen 2026-08-11
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout Ignore IPC errors for pipeline state change if the firmware state is crashed or the IPC has timed out. If the firmware has crashed the kernel still needs to go through the state changes to reset its internal to be able to correctly work the next time the DSP is booted up. The case with IPC timeout is a bit more problematic, but it has been rootcaused to be the result of system scheduling blockage and the firmware did actually received and handled the message, but the reply handling got blocked by issues outside of the SOF stack. So far the best way to handle this is to continue with setting the state.

CSIRTS triage

What
ASoC SOF IPC4 PCM pipeline trigger does not recover cleanly on IPC timeout, leaving pipeline in inconsistent state.
Who is affected
Systems using Sound Open Firmware with IPC4 mode and PCM playback.
Urgency
Low priority; denial of service requires specific timeout condition and manual recovery typically available.
Action
Apply patch to continue pipeline trigger process on IPC timeout condition.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-80581

Get an email if CVE-2026-80581 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-80581

CVE.org record

Embed the live status

CVE-2026-80581 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-80581 status](https://www.csirts.com/badge/CVE-2026-80581)](https://www.csirts.com/cve/CVE-2026-80581)