๐Ÿ” CVE Alert

CVE-2026-64485

UNKNOWN 0.0

ALSA: compress: Fix task creation error unwind

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: ALSA: compress: Fix task creation error unwind snd_compr_task_new() allocates the driver task before validating the returned DMA buffers and reserving file descriptors. When either of those later steps fails, the core frees its task wrapper and DMA-buffer references without calling the driver's task_free() callback. Any driver resources allocated by task_create() are therefore leaked. The dual-fd allocation path also jumps to cleanup without storing the negative get_unused_fd_flags() result in retval. Since retval still contains the successful task_create() return value, TASK_CREATE can incorrectly report success although the task was discarded. Preserve the fd allocation errors and call task_free() when failure occurs after a successful task_create() callback.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
04177158cf98a79744937893b100020d77e6f9ac < b27a75d42044d9d4709095617730b91b1c4af423 04177158cf98a79744937893b100020d77e6f9ac < 426a9947a38d272d0e19c031658da68e31128667 04177158cf98a79744937893b100020d77e6f9ac < 4a60127debb9e370d6c0e22a307326b624a141f3
Linux / Linux
6.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/b27a75d42044d9d4709095617730b91b1c4af423 git.kernel.org: https://git.kernel.org/stable/c/426a9947a38d272d0e19c031658da68e31128667 git.kernel.org: https://git.kernel.org/stable/c/4a60127debb9e370d6c0e22a307326b624a141f3