CVE-2026-72301: ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get
In the Linux kernel, the following vulnerability has been resolved:
ASoC: SOF: ipc3-control: Fix TOCTOU in bytesput and bytesget
In sofipc3bytesput(), the size used for the memcpy is derived from the old data->size already in the buffer, not the incoming new data's size field. If the new data has a different size, the copy length is wrong: it may truncate valid data or copy stale bytes.
Similarly, sofipc3bytesget() checks data->size against maxsize without accounting for the sizeof(struct sofipcctrldata) offset of the flex array within the allocation.
Fix bytesput to validate and use the incoming data's sofabihdr.size from ucontrol before copying. Fix bytesget to subtract sizeof(cdata) from the bounds check to match the actual available space.