SB2026072783 - NULL pointer dereference in Linux kernel isa gus
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) NULL pointer dereference (CVE-ID: CVE-2026-64482)
CWE-ID: CWE-476 - NULL Pointer Dereference
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in snd_gf1_pcm_volume_control() when handling a failed snd_ctl_new1() allocation. A local user can trigger a memory allocation failure leading to a NULL dereference to cause a denial of service.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/465075c6835103821d725c13f8c545898e5f2636
- https://git.kernel.org/stable/c/5e74e5e8cb7cc25f7a89f59abaf3489bf0c6f4a0
- https://git.kernel.org/stable/c/97f6bdf5d5ded2e37f358cacb5a95f1393356604
- https://git.kernel.org/stable/c/c7fa99d30c7a166a5e5db5a585ce7501ff68326b
- https://git.kernel.org/stable/c/eccf8e91266e39f6f15637702a04a1d344833fe2
- https://git.kernel.org/stable/c/fc5d4f27ca1293bc1379ef8fff691c30d9803ca2