Answer in brief
CVE-2026-64485 records a Unknown severity vulnerability in ALSA: compress: Fix task creation error unwind. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=04177158cf98a79744937893b100020d77e6f9ac <b27a75d42044d9d4709095617730b91b1c4af423 || >=04177158cf98a79744937893b100020d77e6f9ac <426a9947a38d272d0e19c031658da68e31128667 || >=04177158cf98a79744937893b100020d77e6f9ac <4a60127debb9e370d6c0e22a307326b624a141f3 | b27a75d42044d9d4709095617730b91b1c4af423, 426a9947a38d272d0e19c031658da68e31128667, 4a60127debb9e370d6c0e22a307326b624a141f3 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: compress: Fix task creation error unwind snd_compr_task_new() allocates the driver task before validating the returned DMA buffers and reserving file descriptors. When either of those later steps fails, the core frees its task wrapper and DMA-buffer references without calling the driver's task_free() callback. Any driver resources allocated by task_create() are therefore leaked. The dual-fd allocation path also jumps to cleanup without storing the negative get_unused_fd_flags() result in retval. Since retval still contains the successful task_create() return value, TASK_CREATE can incorrectly report success although the task was discarded. Preserve the fd allocation errors and call task_free() when failure occurs after a successful task_create() callback.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-64485 records a Unknown severity vulnerability in ALSA: compress: Fix task creation error unwind. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=04177158cf98a79744937893b100020d77e6f9ac <b27a75d42044d9d4709095617730b91b1c4af423 || >=04177158cf98a79744937893b100020d77e6f9ac <426a9947a38d272d0e19c031658da68e31128667 || >=04177158cf98a79744937893b100020d77e6f9ac <4a60127debb9e370d6c0e22a307326b624a141f3 | b27a75d42044d9d4709095617730b91b1c4af423, 426a9947a38d272d0e19c031658da68e31128667, 4a60127debb9e370d6c0e22a307326b624a141f3 |
| Linux/Linuxgeneric | 6.13 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 5, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 5, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: compress: Fix task creation error unwind snd_compr_task_new() allocates the driver task before validating the returned DMA buffers and reserving file descriptors. When either of those later steps fails, the core frees its task wrapper and DMA-buffer references without calling the driver's task_free() callback. Any driver resources allocated by task_create() are therefore leaked. The dual-fd allocation path also jumps to cleanup without storing the negative get_unused_fd_flags() result in retval. Since retval still contains the successful task_create() return value, TASK_CREATE can incorrectly report success although the task was discarded. Preserve the fd allocation errors and call task_free() when failure occurs after a successful task_create() callback.
Quoted source text, attributed separately from HOL analysis.