ALSA Vulnerability in Linux Kernel Affecting Traktor Kontrol S4 by Native Instruments
CVE-2026-64487

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64487?

An out-of-bounds read vulnerability in the ALSA subsystem of the Linux kernel affects the Traktor Kontrol S4 input parser. This issue arises when the snd_usb_caiaq_tks4_dispatch function processes input stream messages. Due to an improper handling of the length value, the process can lead to excessive memory access beyond the intended buffer boundaries, posing risks of data corruption or system instability. The issue has been rectified by refining the iteration logic to handle only full message blocks, eliminating the potential for unsigned underflow that could exploit memory boundaries.

Affected Version(s)

Linux 15c5ab607045e278ebf4d2ca4aea2250617d50ca

Linux 15c5ab607045e278ebf4d2ca4aea2250617d50ca < 70d6d4cfa4ad09688aed2ec8a0cfa72c31f60334

Linux 15c5ab607045e278ebf4d2ca4aea2250617d50ca < 884f575cc6acb136eb4a161d925147f85b59c27e

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.