CVE-2026-80581
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc4-pcm: Continue the pipeline trigger in case of IPC timeout
Ignore IPC errors for pipeline state change if the firmware state is
crashed or the IPC has timed out.
If the firmware has crashed the kernel still needs to go through the state
changes to reset its internal to be able to correctly work the next time
the DSP is booted up.
The case with IPC timeout is a bit more problematic, but it has been
rootcaused to be the result of system scheduling blockage and the firmware
did actually received and handled the message, but the reply handling got
blocked by issues outside of the SOF stack.
So far the best way to handle this is to continue with setting the state.
CSIRTS triage
- What
- ASoC SOF IPC4 PCM pipeline trigger does not recover cleanly on IPC timeout, leaving pipeline in inconsistent state.
- Who is affected
- Systems using Sound Open Firmware with IPC4 mode and PCM playback.
- Urgency
- Low priority; denial of service requires specific timeout condition and manual recovery typically available.
- Action
- Apply patch to continue pipeline trigger process on IPC timeout condition.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-80581
Get an email if CVE-2026-80581 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
Advisory coverage (2)
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-80581)