CVE-2026-64485

7.8

Linux · Kernel

A task creation error unwind flaw in the Linux kernel ALSA compress component allows a local authenticated attacker to cause resource leaks and incorrect status reporting.

Executive summary

An improper task creation error unwind flaw in the Linux kernel ALSA compress component affects the Linux Kernel, creating local privilege escalation and system compromise risks.

Vulnerability

This is a resource management and error handling flaw in the ALSA compress driver task creation function, requiring local access with low privileges and no user interaction.

Business impact

A successful exploit of this vulnerability could allow a local authenticated user to compromise confidentiality, integrity, and availability of the affected system through resource leaks and improper error handling. With a CVSS score of 7.8, this high-severity flaw threatens underlying host stability and security if unpatched.

Remediation

Immediate Action: Update the Linux kernel to version 6.18.39, 7.1.4, or later depending on the active release branch, or apply the official fix commits.

Proactive Monitoring: Monitor system logs for kernel resource allocation failures or anomalous error codes related to ALSA compress audio tasks.

Compensating Controls: Restrict local shell access and auditing user privileges to minimize the risk of unauthorized local execution.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high severity score and potential for complete system compromise via local vector, administrators should prioritize updating the Linux kernel to the corrected versions. Immediate application of the upstream patch prevents resource leaks and potential privilege escalation.

More Linux CVEs

Sources