Junglewise Threat Intelligence

CVE-2026-64489: Linux Kernel NULL pointer dereference in ALSA ymfpci driver

CVE-2026-64489 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's ALSA sound driver for Yamaha YMFPCI audio cards. Under specific low-memory conditions, the system could experience a kernel crash (NULL pointer dereference) when attempting to initialize audio controls. This could lead to a local denial-of-service, impacting system stability.

Technical details

A vulnerability exists in the snd_ymfpci_create_spdif_controls() function within sound/pci/ymfpci/ymfpci_main.c of the Linux kernel. The function calls snd_ctl_new1() to allocate new control structures but fails to validate the return value. If memory allocation fails and returns NULL, the code subsequently dereferences the kctl pointer to initialize kctl->id.device, resulting in a NULL pointer dereference. This is a local vulnerability that can be triggered during mixer initialization or configuration. Patches have been released across multiple stable kernel branches to add the necessary NULL checks and return -ENOMEM on failure.

Affected products

  • Linux Linux 6.1.34 to 6.1.178, 6.3.8 to 6.4, 6.4 and later versions prior to 6.6.145, 6.12.96, 6.18.39

Timeline

  • 2026-05-27: other: Vulnerability fix authored
  • 2026-07-25: advisory: CVE published by kernel.org and NVD

References