Null Pointer Dereference in Linux Kernel ALSA - Affected Products
CVE-2026-64488

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64488?

A vulnerability in the Linux kernel's ALSA component can cause a NULL pointer dereference due to insufficient checks after memory allocation for sound control elements. When the snd_ctl_new1() function fails to allocate memory, the absence of checks can lead to dereferencing a null pointer, potentially causing unexpected behavior or system crashes. Proper validation protocols must be implemented to ensure robust handling of memory allocation failures.

Affected Version(s)

Linux f3d9478b2ce468c3115b02ecae7e975990697f15

Linux f3d9478b2ce468c3115b02ecae7e975990697f15

Linux f3d9478b2ce468c3115b02ecae7e975990697f15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.