Answer in brief
CVE-2026-64488 records a Unknown severity vulnerability in ALSA: aoa: check snd_ctl_new1() return value. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
Answer in brief
CVE-2026-64488 records a Unknown severity vulnerability in ALSA: aoa: check snd_ctl_new1() return value. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f3d9478b2ce468c3115b02ecae7e975990697f15 <b0154ebc6dc552c389a574b1e221d728e10346e7 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <d62624fe256b2d0d13454c78cbfc70ff5d954dc7 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <e5e8c4508d95af82f9b4d065f658e5476a8e9bc8 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <d73067e2bbf3775a495d9f38e38d0a3cf53ee790 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <fd786466889e4a6e6de0f4462bd0068edea63960 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <e47f2a341adbac001b6f5d0211b0cd1c1668637b || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <8df560fefe6fed6a20b7e06720eeaeccec349ac0 | b0154ebc6dc552c389a574b1e221d728e10346e7, d62624fe256b2d0d13454c78cbfc70ff5d954dc7, e5e8c4508d95af82f9b4d065f658e5476a8e9bc8, 2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd, d73067e2bbf3775a495d9f38e38d0a3cf53ee790, fd786466889e4a6e6de0f4462bd0068edea63960, e47f2a341adbac001b6f5d0211b0cd1c1668637b, 8df560fefe6fed6a20b7e06720eeaeccec349ac0 |
| Linux/Linuxgeneric | 2.6.18 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: aoa: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. In layout.c, the function does not check the return value before dereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can lead to a NULL pointer dereference. Add NULL checks after snd_ctl_new1() calls and return early if any fails.
Quoted source text, attributed separately from HOL analysis.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f3d9478b2ce468c3115b02ecae7e975990697f15 <b0154ebc6dc552c389a574b1e221d728e10346e7 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <d62624fe256b2d0d13454c78cbfc70ff5d954dc7 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <e5e8c4508d95af82f9b4d065f658e5476a8e9bc8 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <d73067e2bbf3775a495d9f38e38d0a3cf53ee790 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <fd786466889e4a6e6de0f4462bd0068edea63960 || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <e47f2a341adbac001b6f5d0211b0cd1c1668637b || >=f3d9478b2ce468c3115b02ecae7e975990697f15 <8df560fefe6fed6a20b7e06720eeaeccec349ac0 | b0154ebc6dc552c389a574b1e221d728e10346e7, d62624fe256b2d0d13454c78cbfc70ff5d954dc7, e5e8c4508d95af82f9b4d065f658e5476a8e9bc8, 2ee9c46fd2dcd529cef18e37636ee12f5c3dbedd, d73067e2bbf3775a495d9f38e38d0a3cf53ee790, fd786466889e4a6e6de0f4462bd0068edea63960, e47f2a341adbac001b6f5d0211b0cd1c1668637b, 8df560fefe6fed6a20b7e06720eeaeccec349ac0 |
| Linux/Linuxgeneric | 2.6.18 | Not reported |
Published upstream
Jul 25, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 17, 2026
In the Linux kernel, the following vulnerability has been resolved: ALSA: aoa: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. In layout.c, the function does not check the return value before dereferencing ctl->id.name or passing to aoa_snd_ctl_add(), which can lead to a NULL pointer dereference. Add NULL checks after snd_ctl_new1() calls and return early if any fails.
Quoted source text, attributed separately from HOL analysis.