CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-64484

mediumCVSS 5.5covered by 2 sourcesfirst seen 2026-07-14
In the Linux kernel, the following vulnerability has been resolved: ALSA: es1938: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. snd_es1938_mixer() does not check the return value before dereferencing the pointer, which can lead to a NULL pointer dereference. Add a NULL check after snd_ctl_new1() and return -ENOMEM if it fails.

CSIRTS triage

Other
What
A check for the return value of snd_ctl_new1() is missing in the es1938 ALSA driver.
Who is affected
Affected systems using the es1938 ALSA driver.
Urgency
The urgency is unclear due to unknown severity.
Action
Monitor for updates regarding this vulnerability.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-64484

Get an email if CVE-2026-64484 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-64484

CVE.org record

Embed the live status

CVE-2026-64484 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-64484 status](https://www.csirts.com/badge/CVE-2026-64484)](https://www.csirts.com/cve/CVE-2026-64484)