Heap Information Leak in Linux Kernel ALSA's snd_seq_event_dup() Function
CVE-2026-64479

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64479?

The snd_seq_event_dup() function in the Advanced Linux Sound Architecture (ALSA) of the Linux kernel has an uninitialized heap leak issue. This vulnerability arises when data is copied into a pool cell during the processing of MIDI events. If the event size is smaller than the expected cell size in certain configurations, leftover data remains in the memory, leading to potential information disclosure when delivered to unprivileged clients. This leak can expose sensitive heap data to clients, posing a significant risk of unintended information exposure.

Affected Version(s)

Linux 6389f2c135311c4ce7c08c3b29145c8f95aacf1f

Linux d7e2ce72833bb23a82b4201fbed7214cc04a4a8c

Linux 46397622a3fa8372b8fda0f04b33d16923b03b1b

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.