Linux Kernel ALSA Vulnerability in Virtio-snd Control Handling
CVE-2026-64490

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
25 July 2026

What is CVE-2026-64490?

A vulnerability in the Linux kernel's ALSA subsystem for virtio-snd control handling has been identified. The issue arises when the control type and value count provided by the device are not properly validated. This flaw allows a buggy or malicious device to potentially manipulate the control metadata, leading to out-of-bounds access during operations that utilize the g_v2a_type_map and fixed-size arrays. The vulnerability can be exploited through crafted device responses, making it essential for the control type and count to be validated in the parsing function to enhance security.

Affected Version(s)

Linux d6568e3de42dd971a1356f7ba581e6600d53f0a0 < 3243563f99ef5d3949b934bd6390a5679405d0e1

Linux d6568e3de42dd971a1356f7ba581e6600d53f0a0 < 5da9742de22db0dbaa8d414214ab5e1bedde00f9

Linux d6568e3de42dd971a1356f7ba581e6600d53f0a0 < 21584672fd699abe1768241d6c501b2de6139b6a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.