What is CVE-2026-12232?
CVE-2026-12232 is an out-of-bounds read vulnerability in the Intel ALH digital-audio interface driver function 'dai_alh_get_properties()' due to lack of validation on the 'stream_id' parameter. A local authenticated attacker could exploit this to achieve limited information disclosure or privilege escalation. Users should apply the Intel security update.
Azərbaycanca: CVE-2026-12232 Intel ALH rəqəmsal-audio interfeys sürücüsündə "dai_alh_get_properties()" funksiyasında "stream_id" parametrinin yoxlanılmaması səbəbindən massivdən kənar oxuma zəifliyidir. Bu, təsdiqlənməmiş yerli hücumçuya sistem kontekstində məhdud məlumat sızması və ya imtiyaz artımı əldə etməyə imkan verə bilər. İstifadəçilərə Intel-in təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125; shared vendor: Intel
FAQ2
In which Intel component was CVE-2026-12232 discovered?
The vulnerability was discovered in the Intel ALH digital-audio interface driver, in the 'dai_alh_get_properties()' function.
What conditions must an attacker meet to exploit CVE-2026-12232?
The attacker must have unauthenticated local access.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.