SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64485

HIGH · CVSS 7.8 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's ALSA subsystem, specifically in the `snd_compr_task_new()` function, where improper handling of DMA buffer validation and file descriptor reservation can lead to resource leaks. This flaw may result in degraded system performance or instability due to leaked driver resources, potentially allowing for denial-of-service conditions. System administrators and developers managing Linux-based environments should prioritize patching this vulnerability to mitigate associated risks.

CVE
CVE-2026-64485
Severity
HIGH
CVSS
7.8
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: compress: Fix task creation error unwind snd_compr_task_new() allocates the driver task before validating the returned DMA buffers and reserving file descriptors. When either of those later steps fails, the core frees its task wrapper and DMA-buffer references without calling the driver's task_free() callback. Any driver resources allocated by task_create() are therefore leaked. The dual-fd allocation path also jumps to cleanup without storing the negative get_unused_fd_flags() result in retval. Since retval still contains the successful task_create() return value, TASK_CREATE can incorrectly report success although the task was discarded. Preserve the fd allocation errors and call task_free() when failure occurs after a successful task_create() callback.