In the Linux kernel, the following vulnerability has been resolved:
ALSA: cmipci: check sndctlnew1() return value
sndctlnew1() can return NULL when memory allocation fails. sndcmipcispdif_controls() does not check the return value before dereferencing kctl->id.device, which can lead to a NULL pointer dereference.
Add NULL checks after sndctlnew1() calls and return -ENOMEM if any fails.
{
"cna_assigner": "Linux",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64486.json"
}