Linux Kernel ALSA Ice1712 Driver Vulnerability Impacting Audio Systems
CVE-2026-64480

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64480?

The Linux kernel ALSA subsystem contains a flaw within the ice1712 audio driver that fails to validate the return value of the snd_ctl_new1() function. This oversight can lead to NULL pointer dereferences if memory allocation fails, potentially causing crashes or unexpected behaviors in audio systems. The vulnerability has been addressed by implementing necessary NULL checks following calls to snd_ctl_new1() and returning an appropriate error code in case of memory allocation failures, enhancing the reliability and stability of the affected drivers.

Affected Version(s)

Linux 0df0097ea2d52401c31e550389ac758c90e6a1eb < 57d59be545b309d4bb54ac472b15d1e67f254d95

Linux b9a4efd61b6b9f62f83752959e75a5dae20624fa < 69bf1dfa3215524c4ae255bb9dce0770875abbeb

Linux b9a4efd61b6b9f62f83752959e75a5dae20624fa

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.