ALSA: pcm: Don't setup bogus iov_iter for silencing
Summary
| CVE | CVE-2026-64134 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-19 16:17:55 UTC |
| Updated | 2026-07-19 16:17:55 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
ALSA: pcm: Don't setup bogus iov_iter for silencing
At transition to the iov_iter for PCM data transfer, we blindly
applied the iov_iter setup also for silencing (i.e. data = NULL), and
it leads to a calculation of bogus iov_iter. Fortunately this didn't
cause troubles on most of architectures but it goes wrong on RISC-V
now, causing a NULL dereference.
Handle the NULL data case to treat the silencing in interleaved_copy()
for addressing the bug above. noninterleaved_copy() has already the
NULL data handling, so it doesn't need changes. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected cf393babb37a1679a1ec1d864df1090353465e23 41a766c647294842c9b17672449f8e011048cba9 git |
Not specified |
| CNA |
Linux |
Linux |
affected cf393babb37a1679a1ec1d864df1090353465e23 ce836587e594af39ff048d9b29dee0f5f10692c9 git |
Not specified |
| CNA |
Linux |
Linux |
affected cf393babb37a1679a1ec1d864df1090353465e23 feff0251386aa6bb180a0a1cf7c1f91ba868113d git |
Not specified |
| CNA |
Linux |
Linux |
affected cf393babb37a1679a1ec1d864df1090353465e23 c9f6768515818d71bdfc20119a81f3332c53b9c6 git |
Not specified |
| CNA |
Linux |
Linux |
affected cf393babb37a1679a1ec1d864df1090353465e23 e4d3386b74fba8e01280484b67ee481ece00201e git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.6 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.142 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.92 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.34 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.0.11 7.0.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/c9f6768515818d71bdfc20119a81f3332c53b9c6 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/e4d3386b74fba8e01280484b67ee481ece00201e |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ce836587e594af39ff048d9b29dee0f5f10692c9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/41a766c647294842c9b17672449f8e011048cba9 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/feff0251386aa6bb180a0a1cf7c1f91ba868113d |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.