Executive brief
A vulnerability was identified in the Linux kernel's ALSA sound driver for Yamaha YMFPCI audio cards. Under specific low-memory conditions, the system could experience a kernel crash (NULL pointer dereference) when attempting to initialize audio controls. This could lead to a local denial-of-service, impacting system stability.
Technical details
A vulnerability exists in the snd_ymfpci_create_spdif_controls() function within sound/pci/ymfpci/ymfpci_main.c of the Linux kernel. The function calls snd_ctl_new1() to allocate new control structures but fails to validate the return value. If memory allocation fails and returns NULL, the code subsequently dereferences the kctl pointer to initialize kctl->id.device, resulting in a NULL pointer dereference. This is a local vulnerability that can be triggered during mixer initialization or configuration. Patches have been released across multiple stable kernel branches to add the necessary NULL checks and return -ENOMEM on failure.
Affected products
- Linux Linux 6.1.34 to 6.1.178, 6.3.8 to 6.4, 6.4 and later versions prior to 6.6.145, 6.12.96, 6.18.39
Timeline
- 2026-05-27: other: Vulnerability fix authored
- 2026-07-25: advisory: CVE published by kernel.org and NVD
References
- https://git.kernel.org/stable/c/02f33c2062c75e28abc7ad58ce86451cf3140455
- https://git.kernel.org/stable/c/18ec7d7785be7a4ee8ea11e355122282caad4267
- https://git.kernel.org/stable/c/91095474eea29b95c9a8bceb9b501a2702b6c55f
- https://git.kernel.org/stable/c/d7c71dfd4b80f0eacac2c157a8a3a4c6e8b2e0d1
- https://git.kernel.org/stable/c/e64d170346d00b580c0043de3e5ccb3e331c47d4
- https://git.kernel.org/stable/c/f6538a318947b627710b08a268bc80a48c23bde7