ALSA: ice1712: check snd_ctl_new1() return value

Summary

CVECVE-2026-64480
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-25 10:17:33 UTC
Updated2026-07-25 10:17:33 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: ALSA: ice1712: check snd_ctl_new1() return value snd_ctl_new1() can return NULL when memory allocation fails. The ice1712 driver calls snd_ctl_new1() without checking the return value before dereferencing the pointer in multiple places (ice1712.c, ice1724.c, aureon.c), which can lead to NULL pointer dereferences. Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any fails.

Risk And Classification

EPSS: 0.001810000 probability, percentile 0.079700000 (date 2026-07-28)

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 0df0097ea2d52401c31e550389ac758c90e6a1eb 57d59be545b309d4bb54ac472b15d1e67f254d95 git Not specified
CNA Linux Linux affected b9a4efd61b6b9f62f83752959e75a5dae20624fa 69bf1dfa3215524c4ae255bb9dce0770875abbeb git Not specified
CNA Linux Linux affected b9a4efd61b6b9f62f83752959e75a5dae20624fa d34ad480b8896d2b486e2cf29ce1790326cad205 git Not specified
CNA Linux Linux affected b9a4efd61b6b9f62f83752959e75a5dae20624fa 71b87108ad93d433cdb20704a8dc8852304cf2c2 git Not specified
CNA Linux Linux affected b9a4efd61b6b9f62f83752959e75a5dae20624fa 38a7cc46370a57122fb29c4bfe48a851c0c64459 git Not specified
CNA Linux Linux affected b9a4efd61b6b9f62f83752959e75a5dae20624fa 2b929b91b0f3bc6de8a844370049cd99ee8e31ff git Not specified
CNA Linux Linux affected 286e17a1c3baeb1b1cd36b63ee16e8a6e63d558e git Not specified
CNA Linux Linux affected 6.1.34 6.1.178 semver Not specified
CNA Linux Linux affected 6.3.8 6.4 semver Not specified
CNA Linux Linux affected 6.4 Not specified
CNA Linux Linux unaffected 6.4 semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.96 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/69bf1dfa3215524c4ae255bb9dce0770875abbeb 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/d34ad480b8896d2b486e2cf29ce1790326cad205 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/71b87108ad93d433cdb20704a8dc8852304cf2c2 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/57d59be545b309d4bb54ac472b15d1e67f254d95 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/2b929b91b0f3bc6de8a844370049cd99ee8e31ff 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/38a7cc46370a57122fb29c4bfe48a851c0c64459 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report