Linux Kernel ALSA Ice1712 Driver Vulnerability Impacting Audio Systems
CVE-2026-64480
What is CVE-2026-64480?
The Linux kernel ALSA subsystem contains a flaw within the ice1712 audio driver that fails to validate the return value of the snd_ctl_new1() function. This oversight can lead to NULL pointer dereferences if memory allocation fails, potentially causing crashes or unexpected behaviors in audio systems. The vulnerability has been addressed by implementing necessary NULL checks following calls to snd_ctl_new1() and returning an appropriate error code in case of memory allocation failures, enhancing the reliability and stability of the affected drivers.
Affected Version(s)
Linux 0df0097ea2d52401c31e550389ac758c90e6a1eb < 57d59be545b309d4bb54ac472b15d1e67f254d95
Linux b9a4efd61b6b9f62f83752959e75a5dae20624fa < 69bf1dfa3215524c4ae255bb9dce0770875abbeb
Linux b9a4efd61b6b9f62f83752959e75a5dae20624fa