CVE-2026-64484

medium

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: es1938: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. snd_es1938_mixer() does not check the return value before dereferencing the pointer, which can lead to a NULL pointer dereference. Add a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.

References

https://git.kernel.org/stable/c/af01c48e17a66fa038af210a5c49d6cdefd210bd

https://git.kernel.org/stable/c/9e53e99b6fa3cd82992d963cbff58dbbd1df8651

https://git.kernel.org/stable/c/96cad5bd7d0a176db3fdc06717a41271247336bd

https://git.kernel.org/stable/c/7531a37720c2545a480fd0fa464978569bf9d6a2

https://git.kernel.org/stable/c/6c4efebaf73e217efbd08cdbda805758a7db3680

https://git.kernel.org/stable/c/41759affbcfe3d51a32900da9547a1ffd744a85f

https://git.kernel.org/stable/c/1edd1f02dddd20aeb6066ded41017615766ea42f

https://git.kernel.org/stable/c/1949163dee39e0e4a1468f37dd7302962f6af45a

Details

Source: Mitre, NVD

Published: 2026-07-25

Updated: 2026-07-25

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 5.5

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

EPSS

EPSS: 0.0022