PT-2026-64702 · Linux+1 · Linux Kernel+1

CVE-2026-64481

·

Published

2026-07-25

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the ALSA hda/cs35l41 component where cs35l41 hda creates ALSA controls with private data pointing to the cs35l41 hda object. The firmware load control can queue fw load work. Because these controls are not removed during component unbind, and the cs35l41 remove dsp() helper is skipped when halo initialized is false, a firmware load can be requested before the DSP is initialized if firmware autostart is disabled. If the component or device is removed before the queued work executes, the worker may run after teardown and dereference invalid driver state.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-64481
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu