{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64490","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.792Z","datePublished":"2026-07-25T08:51:48.877Z","dateUpdated":"2026-08-17T04:56:38.207Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:56:38.207Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: virtio: Validate control metadata from the device\n\nvirtio-snd control handling trusts the device-provided control type and\nvalue count returned by the device.\n\nThat metadata is then used directly to index g_v2a_type_map[] in\nvirtsnd_kctl_info(), and to size loops and memcpy() operations in\nvirtsnd_kctl_get() and virtsnd_kctl_put() against fixed-size\nvirtio_snd_ctl_value and snd_ctl_elem_value arrays.\n\nA buggy or malicious device can therefore trigger out-of-bounds access by\nadvertising an invalid control type or an oversized value count.\n\nValidate control type and count once in virtsnd_kctl_parse_cfg(), before\nquerying enumerated items or exposing the control to ALSA."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.4,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The malformed metadata arrives through a locally attached virtio-snd device/backend and reaches vulnerable ALSA callbacks through local control operations. No routable network path or physical attachment is required.\nAC:L - The backend directly controls the type, count, access flags, and returned values, allowing deterministic oversized loops or copies without a race. Repeated control notifications and operations permit reliable triggering and heap grooming.\nPR:N - A malicious virtio backend supplies metadata during device initialization without guest authentication or capability checks. Standard OSS mixer registration or an automatically running audio service can subsequently access the control without the attacker holding guest credentials.\nUI:N - No human action is required because OSS mixer construction and normal audio-service enumeration can query or operate newly registered controls automatically. The backend can also generate control-change notifications to provoke further accesses.\nS:U - The vulnerable driver and corrupted kernel memory are within the same guest-kernel security authority. This is host-to-guest device exploitation, not a guest-to-host escape or IOMMU-boundary bypass.\nC:H - Oversized read operations copy data beyond the fixed 512-byte response into the userspace-returned ALSA value structure, exposing adjacent kernel heap contents. The unchecked type-map index also provides a device-selected out-of-bounds kernel read.\nI:H - Oversized INTEGER64, ENUMERATED, and BYTES write operations copy control values beyond the 512-byte virtio request payload into adjacent kernel heap objects. This controlled heap corruption can plausibly provide arbitrary modification or control-flow hijacking.\nA:H - Invalid type indices, enormous loops or memcpy lengths, and resulting heap corruption can cause an immediate kernel fault, oops, panic, or hang. The malicious backend can trigger the condition repeatedly."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/virtio/virtio_kctl.c"],"versions":[{"version":"d6568e3de42dd971a1356f7ba581e6600d53f0a0","lessThan":"3243563f99ef5d3949b934bd6390a5679405d0e1","status":"affected","versionType":"git"},{"version":"d6568e3de42dd971a1356f7ba581e6600d53f0a0","lessThan":"5da9742de22db0dbaa8d414214ab5e1bedde00f9","status":"affected","versionType":"git"},{"version":"d6568e3de42dd971a1356f7ba581e6600d53f0a0","lessThan":"21584672fd699abe1768241d6c501b2de6139b6a","status":"affected","versionType":"git"},{"version":"d6568e3de42dd971a1356f7ba581e6600d53f0a0","lessThan":"c77a6cbb36ff8cbc1f084d94f8dcda5250935271","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["sound/virtio/virtio_kctl.c"],"versions":[{"version":"6.9","status":"affected"},{"version":"0","lessThan":"6.9","status":"unaffected","versionType":"semver"},{"version":"6.12.96","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.12.96"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.9","versionEndExcluding":"7.2"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/3243563f99ef5d3949b934bd6390a5679405d0e1"},{"url":"https://git.kernel.org/stable/c/5da9742de22db0dbaa8d414214ab5e1bedde00f9"},{"url":"https://git.kernel.org/stable/c/21584672fd699abe1768241d6c501b2de6139b6a"},{"url":"https://git.kernel.org/stable/c/c77a6cbb36ff8cbc1f084d94f8dcda5250935271"}],"title":"ALSA: virtio: Validate control metadata from the device","x_generator":{"engine":"bippy-1.2.0"}}}}