CVE-2026-64486EPSS p10.8%
CVE-2026-64486CVE-2026-64486
Description
In the Linux kernel, the following vulnerability has been resolved:
ALSA: cmipci: check snd_ctl_new1() return value
snd_ctl_new1() can return NULL when memory allocation fails.
snd_cmipci_spdif_controls() does not check the return value before
dereferencing kctl->id.device, which can lead to a NULL pointer
dereference.
Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any
fails.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 10.8% · 2026-10-06T12:00:23Z |
| Last modified | 2026-08-17 |