NULL pointer dereference in Linux kernel - CVE-2026-64482
Published: July 27, 2026
Vulnerability identifier: #VU139460
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64482
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to a NULL pointer dereference in snd_gf1_pcm_volume_control() when handling a failed snd_ctl_new1() allocation. A local user can trigger a memory allocation failure leading to a NULL dereference to cause a denial of service.
Affected software
Linux kernel
How to mitigate CVE-2026-64482
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/465075c6835103821d725c13f8c545898e5f2636
- https://git.kernel.org/stable/c/5e74e5e8cb7cc25f7a89f59abaf3489bf0c6f4a0
- https://git.kernel.org/stable/c/97f6bdf5d5ded2e37f358cacb5a95f1393356604
- https://git.kernel.org/stable/c/c7fa99d30c7a166a5e5db5a585ce7501ff68326b
- https://git.kernel.org/stable/c/eccf8e91266e39f6f15637702a04a1d344833fe2
- https://git.kernel.org/stable/c/fc5d4f27ca1293bc1379ef8fff691c30d9803ca2