CVE-2026-64482 is a vulnerability in Linux Kernel
Published on July 25, 2026
ALSA: gus: check snd_ctl_new1() return value
In the Linux kernel, the following vulnerability has been resolved:
ALSA: gus: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_gf1_pcm_volume_control() does not check the return value before
dereferencing kctl->id.index, which can lead to a NULL pointer
dereference.
Add a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.
Products Associated with CVE-2026-64482
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version c35034fd6446afaf408d5ab296068e32c775c965 and below 97f6bdf5d5ded2e37f358cacb5a95f1393356604 is affected.
- Version c5ae57b1bb99bd6f50b90428fabde397c2aeba0f and below eccf8e91266e39f6f15637702a04a1d344833fe2 is affected.
- Version c5ae57b1bb99bd6f50b90428fabde397c2aeba0f and below fc5d4f27ca1293bc1379ef8fff691c30d9803ca2 is affected.
- Version c5ae57b1bb99bd6f50b90428fabde397c2aeba0f and below 5e74e5e8cb7cc25f7a89f59abaf3489bf0c6f4a0 is affected.
- Version c5ae57b1bb99bd6f50b90428fabde397c2aeba0f and below 465075c6835103821d725c13f8c545898e5f2636 is affected.
- Version c5ae57b1bb99bd6f50b90428fabde397c2aeba0f and below c7fa99d30c7a166a5e5db5a585ce7501ff68326b is affected.
- Version a1374d2683442633f8ad2169f8f31df45048e008 is affected.
- Version 6.1.34 and below 6.1.178 is affected.
- Version 6.3.8 and below 6.4 is affected.
- Version 6.4 is affected.
- Before 6.4 is unaffected.
- Version 6.1.178, <= 6.1.* is unaffected.
- Version 6.6.145, <= 6.6.* is unaffected.
- Version 6.12.96, <= 6.12.* is unaffected.
- Version 6.18.39, <= 6.18.* is unaffected.
- Version 7.1.4, <= 7.1.* is unaffected.
- Version 7.2-rc1, <= * is unaffected.