Back to overview

CVE-2026-64134

Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Don't setup bogus iov_iter for silencing At transition to the iov_iter for PCM data transfer, we blindly applied the iov_iter setup also for silencing (i.e. data = NULL), and it leads to a calculation of bogus iov_iter. Fortunately this didn't cause troubles on most of architectures but it goes wrong on RISC-V now, causing a NULL dereference. Handle the NULL data case to treat the silencing in interleaved_copy() for addressing the bug above. noninterleaved_copy() has already the NULL data handling, so it doesn't need changes.

Metadata

CVE ID
CVE-2026-64134
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 15:40 UTC
Last updated
2026-07-19 15:40 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux cf393babb37a1679a1ec1d864df1090353465e23 < 41a766c647294842c9b17672449f8e011048cba9, cf393babb37a1679a1ec1d864df1090353465e23 < ce836587e594af39ff048d9b29dee0f5f10692c9, cf393babb37a1679a1ec1d864df1090353465e23 < feff0251386aa6bb180a0a1cf7c1f91ba868113d, cf393babb37a1679a1ec1d864df1090353465e23 < c9f6768515818d71bdfc20119a81f3332c53b9c6 …
Linux Linux 6.6, 0 < 6.6, 6.6.142 ≤ 6.6.*, 6.12.92 ≤ 6.12.* …
Back to overview