๐Ÿ” CVE Alert

CVE-2026-64001

UNKNOWN 0.0

ALSA: pcm: oss: Fix setup list UAF on proc write error

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix setup list UAF on proc write error snd_pcm_oss_proc_write() links a newly allocated setup entry into the OSS setup list before duplicating the task name. If the task-name allocation fails, the error path frees the already linked entry and leaves setup_list pointing at freed memory. A later OSS device open can then walk the stale list entry in snd_pcm_oss_look_for_setup() and dereference freed memory. Allocate the task name and initialize the setup entry before publishing the entry on setup_list. Also fetch the initial proc read iterator only after taking setup_mutex, so all setup_list traversal follows the same list lifetime rules.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
060d77b9c04acd7aef60790398a53f731db8c8fe < 8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce 060d77b9c04acd7aef60790398a53f731db8c8fe < e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c 060d77b9c04acd7aef60790398a53f731db8c8fe < be387230dc22d870afd0e5d35912b07c2bc323bd 060d77b9c04acd7aef60790398a53f731db8c8fe < 4cc54bdd54b337e77115be5b55577d1c58608eae
Linux / Linux
2.6.17

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce git.kernel.org: https://git.kernel.org/stable/c/e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c git.kernel.org: https://git.kernel.org/stable/c/be387230dc22d870afd0e5d35912b07c2bc323bd git.kernel.org: https://git.kernel.org/stable/c/4cc54bdd54b337e77115be5b55577d1c58608eae