CVE-2026-64134
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
30/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
ALSA: pcm: Don&#39;t setup bogus iov_iter for silencing<br />
<br />
At transition to the iov_iter for PCM data transfer, we blindly<br />
applied the iov_iter setup also for silencing (i.e. data = NULL), and<br />
it leads to a calculation of bogus iov_iter. Fortunately this didn&#39;t<br />
cause troubles on most of architectures but it goes wrong on RISC-V<br />
now, causing a NULL dereference.<br />
<br />
Handle the NULL data case to treat the silencing in interleaved_copy()<br />
for addressing the bug above. noninterleaved_copy() has already the<br />
NULL data handling, so it doesn&#39;t need changes.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/41a766c647294842c9b17672449f8e011048cba9
- https://git.kernel.org/stable/c/c9f6768515818d71bdfc20119a81f3332c53b9c6
- https://git.kernel.org/stable/c/ce836587e594af39ff048d9b29dee0f5f10692c9
- https://git.kernel.org/stable/c/e4d3386b74fba8e01280484b67ee481ece00201e
- https://git.kernel.org/stable/c/feff0251386aa6bb180a0a1cf7c1f91ba868113d



