ALSA: asihpi: Fix potential OOB array access at reading cache
Summary
| CVE | CVE-2026-64133 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:55 UTC |
| Updated | 2026-07-20 07:16:42 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
ALSA: asihpi: Fix potential OOB array access at reading cache
find_control() to retrieve a cached info accesses the array with the
given index blindly, which may lead to an OOB array access.
Add a sanity check for avoiding it. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 719f82d3987aad4cc9f46d19c35f362672545cad e060e21fe9cca1e5eafd8a1c597026577771e8d9 git |
Not specified |
| CNA |
Linux |
Linux |
affected 719f82d3987aad4cc9f46d19c35f362672545cad 34d0d492a2812b9289af14bca3573a89275965b2 git |
Not specified |
| CNA |
Linux |
Linux |
affected 719f82d3987aad4cc9f46d19c35f362672545cad ffa29cea7bf9a4ef2ea8084967f142e0301ac670 git |
Not specified |
| CNA |
Linux |
Linux |
affected 719f82d3987aad4cc9f46d19c35f362672545cad 7b6f8c8eb93f02a74b1de8e521c0952af10d1f43 git |
Not specified |
| CNA |
Linux |
Linux |
affected 719f82d3987aad4cc9f46d19c35f362672545cad 8778386e4387b28f2bf8425d7ffc667c6294457f git |
Not specified |
| CNA |
Linux |
Linux |
affected 719f82d3987aad4cc9f46d19c35f362672545cad 61c5017c64e2ac9e10b70b14b17a079dbc0a805f git |
Not specified |
| CNA |
Linux |
Linux |
affected 719f82d3987aad4cc9f46d19c35f362672545cad 7d107239935793995bdc6cf29bb99e180bde4c28 git |
Not specified |
| CNA |
Linux |
Linux |
affected 719f82d3987aad4cc9f46d19c35f362672545cad 7b7d6572145c1dab2dd9bfb550b188e5f0ff3c3f git |
Not specified |
| CNA |
Linux |
Linux |
affected 2.6.35 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 2.6.35 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.10.258 5.10.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 5.15.209 5.15.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.1.175 6.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.142 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.92 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.34 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.11 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/7b7d6572145c1dab2dd9bfb550b188e5f0ff3c3f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ffa29cea7bf9a4ef2ea8084967f142e0301ac670 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/34d0d492a2812b9289af14bca3573a89275965b2 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/8778386e4387b28f2bf8425d7ffc667c6294457f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7b6f8c8eb93f02a74b1de8e521c0952af10d1f43 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/61c5017c64e2ac9e10b70b14b17a079dbc0a805f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/7d107239935793995bdc6cf29bb99e180bde4c28 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e060e21fe9cca1e5eafd8a1c597026577771e8d9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.