Answer in brief
CVE-2026-64486 records a Unknown severity vulnerability in ALSA: cmipci: check snd_ctl_new1() return value. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3454490e0396191f8f9c215fccf5deef76abffb5 <b44888c33c4f11277d0e5e023338f2740232a4ed || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <8825a06bfa7932a7a74dec01669d405df0b47286 || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <4dd5b0b1a52a8d6e59a3f217204817228ce0238b || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <af2b009b773bc42995546507963e5e78970dc3ed || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <67e9ea92cd598cba1783ff701553c776a6cedee9 || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <c205bd1b28fb7e5f1061a4e78813fad7d315cb3e || 7bf12707fa3db4c14fbe8ab93efb421d8ca93bf8 || >=6.1.34 <6.1.178 || >=6.3.8 <6.4 | b44888c33c4f11277d0e5e023338f2740232a4ed, 8825a06bfa7932a7a74dec01669d405df0b47286, 4dd5b0b1a52a8d6e59a3f217204817228ce0238b, af2b009b773bc42995546507963e5e78970dc3ed, 67e9ea92cd598cba1783ff701553c776a6cedee9, c205bd1b28fb7e5f1061a4e78813fad7d315cb3e, 6.1.178, 6.4 |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: cmipci: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. snd_cmipci_spdif_controls() does not check the return value before dereferencing kctl->id.device, which can lead to a NULL pointer dereference. Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any fails.
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-64486 records a Unknown severity vulnerability in ALSA: cmipci: check snd_ctl_new1() return value. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=3454490e0396191f8f9c215fccf5deef76abffb5 <b44888c33c4f11277d0e5e023338f2740232a4ed || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <8825a06bfa7932a7a74dec01669d405df0b47286 || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <4dd5b0b1a52a8d6e59a3f217204817228ce0238b || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <af2b009b773bc42995546507963e5e78970dc3ed || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <67e9ea92cd598cba1783ff701553c776a6cedee9 || >=f2f312ad88c68a7f4a7789b9269ae33af3c7c7e9 <c205bd1b28fb7e5f1061a4e78813fad7d315cb3e || 7bf12707fa3db4c14fbe8ab93efb421d8ca93bf8 || >=6.1.34 <6.1.178 || >=6.3.8 <6.4 | b44888c33c4f11277d0e5e023338f2740232a4ed, 8825a06bfa7932a7a74dec01669d405df0b47286, 4dd5b0b1a52a8d6e59a3f217204817228ce0238b, af2b009b773bc42995546507963e5e78970dc3ed, 67e9ea92cd598cba1783ff701553c776a6cedee9, c205bd1b28fb7e5f1061a4e78813fad7d315cb3e, 6.1.178, 6.4 |
| Linux/Linuxgeneric | 6.4 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: cmipci: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. snd_cmipci_spdif_controls() does not check the return value before dereferencing kctl->id.device, which can lead to a NULL pointer dereference. Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any fails.
Quoted source text, attributed separately from HOL analysis.