Executive brief
A vulnerability in the Linux kernel's audio subsystem (ALSA) could allow a local user to cause a system crash. The issue occurs when the system attempts to process specific audio data transfers, particularly on RISC-V hardware architectures. This could lead to a denial-of-service, impacting the availability of the affected system.
Technical details
A vulnerability exists in the ALSA (Advanced Linux Sound Architecture) PCM library within the Linux kernel. The root cause is an improper setup of the iov_iter structure during audio 'silencing' operations in the interleaved_copy() function. When data is NULL, the code incorrectly calculates a bogus iov_iter, leading to a NULL pointer dereference. While many architectures handle this gracefully, it consistently triggers a kernel panic on RISC-V systems. The issue was introduced in the transition to iov_iter for PCM data transfers and has been resolved by adding explicit NULL data handling to call fill_silence() instead of proceeding with a transfer.
Affected products
- Linux Linux 6.6 to 6.6.142, 6.12 to 6.12.92, 6.18 to 6.18.34, 7.0 to 7.0.11
Timeline
- 2026-05-17: patched: Initial fix commit by Takashi Iwai
- 2026-07-19: disclosed: CVE-2026-64134 published
References
- https://git.kernel.org/stable/c/41a766c647294842c9b17672449f8e011048cba9
- https://git.kernel.org/stable/c/c9f6768515818d71bdfc20119a81f3332c53b9c6
- https://git.kernel.org/stable/c/ce836587e594af39ff048d9b29dee0f5f10692c9
- https://git.kernel.org/stable/c/e4d3386b74fba8e01280484b67ee481ece00201e
- https://git.kernel.org/stable/c/feff0251386aa6bb180a0a1cf7c1f91ba868113d