CVE-2026-64488

Unknown

Last modified

CVE-2026-64488 is a vulnerability of currently unknown severity. In the Linux kernel, the following vulnerability has been resolved: ALSA: aoa: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. In layout.c, the function does not check the return value before dereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can lead to a NULL pointer dereference. Add NULL checks after snd_ctl_new1() calls and return early if any fails..

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: aoa: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. In layout.c, the function does not check the return value before dereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can lead to a NULL pointer dereference. Add NULL checks after snd_ctl_new1() calls and return early if any fails.

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
LinuxLinux>= f3d9478b2ce468c3115b02ecae7e975990697f15, < b0154ebc6dc552c389a574b1e221d728e10346e7; >= f3d9478b2ce468c3115b02ecae7e975990697f15, < d62624fe256b2d0d13454c78cbfc70ff5d954dc7; >= f3d9478b2ce468c3115b02ecae7e975990697f15, < e5e8c4508d95af82f9b4d065f658e5476a8e9bc8; >= f3d9478b2ce468c3115b02ecae7e975990697f15, < 2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd; >= f3d9478b2ce468c3115b02ecae7e975990697f15, < d73067e2bbf3775a495d9f38e38d0a3cf53ee790; >= f3d9478b2ce468c3115b02ecae7e975990697f15, < fd786466889e4a6e6de0f4462bd0068edea63960; >= f3d9478b2ce468c3115b02ecae7e975990697f15, < e47f2a341adbac001b6f5d0211b0cd1c1668637b; >= f3d9478b2ce468c3115b02ecae7e975990697f15, < 8df560fefe6fed6a20b7e06720eeaeccec349ac0
LinuxLinux2.6.18

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-64488?
In the Linux kernel, the following vulnerability has been resolved: ALSA: aoa: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. In layout.c, the function does not check the return value before dereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can lead to a NULL pointer dereference. Add NULL checks after snd_ctl_new1() calls and return early if any fails.
How severe is CVE-2026-64488?
Severity scoring for CVE-2026-64488 is pending analysis.
How do I fix CVE-2026-64488?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-64488?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST