Answer in brief
CVE-2026-64485 records a High severity (CVSS 7.8) vulnerability in ALSA: compress: Fix task creation error unwind. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 7.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=04177158cf98a79744937893b100020d77e6f9ac <b27a75d42044d9d4709095617730b91b1c4af423 || >=04177158cf98a79744937893b100020d77e6f9ac <426a9947a38d272d0e19c031658da68e31128667 || >=04177158cf98a79744937893b100020d77e6f9ac <4a60127debb9e370d6c0e22a307326b624a141f3 | b27a75d42044d9d4709095617730b91b1c4af423, 426a9947a38d272d0e19c031658da68e31128667, 4a60127debb9e370d6c0e22a307326b624a141f3 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: compress: Fix task creation error unwind snd_compr_task_new() allocates the driver task before validating the returned DMA buffers and reserving file descriptors. When either of those later steps fails, the core frees its task wrapper and DMA-buffer references without calling the driver's task_free() callback. Any driver resources allocated by task_create() are therefore leaked. The dual-fd allocation path also jumps to cleanup without storing the negative get_unused_fd_flags() result in retval. Since retval still contains the successful task_create() return value, TASK_CREATE can incorrectly report success although the task was discarded. Preserve the fd allocation errors and call task_free() when failure occurs after a successful task_create() callback.
Quoted source text, attributed separately from HOL analysis.