Heap Information Leak in Linux Kernel ALSA's snd_seq_event_dup() Function
CVE-2026-64479
Currently unrated
What is CVE-2026-64479?
The snd_seq_event_dup() function in the Advanced Linux Sound Architecture (ALSA) of the Linux kernel has an uninitialized heap leak issue. This vulnerability arises when data is copied into a pool cell during the processing of MIDI events. If the event size is smaller than the expected cell size in certain configurations, leftover data remains in the memory, leading to potential information disclosure when delivered to unprivileged clients. This leak can expose sensitive heap data to clients, posing a significant risk of unintended information exposure.
Affected Version(s)
Linux 6389f2c135311c4ce7c08c3b29145c8f95aacf1f
Linux d7e2ce72833bb23a82b4201fbed7214cc04a4a8c
Linux 46397622a3fa8372b8fda0f04b33d16923b03b1b