Back to overview

CVE-2026-64488

Description
In the Linux kernel, the following vulnerability has been resolved: ALSA: aoa: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. In layout.c, the function does not check the return value before dereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can lead to a NULL pointer dereference. Add NULL checks after snd_ctl_new1() calls and return early if any fails.

Metadata

CVE ID
CVE-2026-64488
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-25 08:51 UTC
Last updated
2026-07-25 08:51 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux f3d9478b2ce468c3115b02ecae7e975990697f15 < b0154ebc6dc552c389a574b1e221d728e10346e7, f3d9478b2ce468c3115b02ecae7e975990697f15 < d62624fe256b2d0d13454c78cbfc70ff5d954dc7, f3d9478b2ce468c3115b02ecae7e975990697f15 < e5e8c4508d95af82f9b4d065f658e5476a8e9bc8, f3d9478b2ce468c3115b02ecae7e975990697f15 < 2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd …
Linux Linux 2.6.18, 0 < 2.6.18, 5.10.261 ≤ 5.10.*, 5.15.212 ≤ 5.15.* …
Back to overview