CVE-2026-64480 PUBLISHED

ALSA: ice1712: check snd_ctl_new1() return value

Assigner: Linux
Reserved: 19.07.2026 Published: 25.07.2026 Updated: 25.07.2026

In the Linux kernel, the following vulnerability has been resolved:

ALSA: ice1712: check snd_ctl_new1() return value

snd_ctl_new1() can return NULL when memory allocation fails. The ice1712 driver calls snd_ctl_new1() without checking the return value before dereferencing the pointer in multiple places (ice1712.c, ice1724.c, aureon.c), which can lead to NULL pointer dereferences.

Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any fails.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 0df0097ea2d52401c31e550389ac758c90e6a1eb to 57d59be545b309d4bb54ac472b15d1e67f254d95 (excl.)
  • affected from b9a4efd61b6b9f62f83752959e75a5dae20624fa to 69bf1dfa3215524c4ae255bb9dce0770875abbeb (excl.)
  • affected from b9a4efd61b6b9f62f83752959e75a5dae20624fa to d34ad480b8896d2b486e2cf29ce1790326cad205 (excl.)
  • affected from b9a4efd61b6b9f62f83752959e75a5dae20624fa to 71b87108ad93d433cdb20704a8dc8852304cf2c2 (excl.)
  • affected from b9a4efd61b6b9f62f83752959e75a5dae20624fa to 38a7cc46370a57122fb29c4bfe48a851c0c64459 (excl.)
  • affected from b9a4efd61b6b9f62f83752959e75a5dae20624fa to 2b929b91b0f3bc6de8a844370049cd99ee8e31ff (excl.)
  • Version 286e17a1c3baeb1b1cd36b63ee16e8a6e63d558e is affected
  • affected from 6.1.34 to 6.1.178 (excl.)
  • affected from 6.3.8 to 6.4 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.4 is affected
  • unaffected from 0 to 6.4 (excl.)
  • unaffected from 6.1.178 to 6.1.* (incl.)
  • unaffected from 6.6.145 to 6.6.* (incl.)
  • unaffected from 6.12.96 to 6.12.* (incl.)
  • unaffected from 6.18.39 to 6.18.* (incl.)
  • unaffected from 7.1.4 to 7.1.* (incl.)
  • unaffected from 7.2-rc1 to * (incl.)

References