Bug 2507086 (CVE-2026-64487)
| Summary: | CVE-2026-64487 kernel: ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | rhel-process-autobot, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in the Linux kernel's sound subsystem, specifically within the ALSA caiaq driver responsible for handling Traktor Kontrol S4 devices. A local attacker, by providing specially crafted input from a connected device, could exploit an out-of-bounds read vulnerability. This issue arises from incorrect handling of input stream lengths, leading to the system reading beyond its allocated memory buffer. Successful exploitation could result in the disclosure of sensitive information from kernel memory or cause a system crash, leading to a denial of service.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-07-25 10:04:15 UTC
|