PT-2026-64708 · Linux+1 · Linux Kernel+1

CVE-2026-64487

·

Published

2026-07-25

·

Updated

2026-09-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An out-of-bounds read exists in the Traktor Kontrol S4 input parser within the ALSA caiaq component. The function snd usb caiaq tks4 dispatch() processes input streams in fixed 16-byte blocks. Because the len variable, derived from urb->actual length, is unsigned and not guaranteed to be a multiple of 16, a trailing block of 1 to 15 bytes causes an unsigned underflow during the subtraction of the block size. This results in the loop continuing to read memory far beyond the end of the 512-byte ep4 in buf until an invalid block ID is encountered.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-93533
CVE-2026-64487
ECHO-7E99-713E-DBA9
OPENSUSE-SU-2026:11476-1
USN-8726-1
USN-8727-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu