PT-2026-64708 · Linux+1 · Linux Kernel+1
CVE-2026-64487
·
Published
2026-07-25
·
Updated
2026-09-07
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
An out-of-bounds read exists in the Traktor Kontrol S4 input parser within the ALSA caiaq component. The function
snd usb caiaq tks4 dispatch() processes input streams in fixed 16-byte blocks. Because the len variable, derived from urb->actual length, is unsigned and not guaranteed to be a multiple of 16, a trailing block of 1 to 15 bytes causes an unsigned underflow during the subtraction of the block size. This results in the loop continuing to read memory far beyond the end of the 512-byte ep4 in buf until an invalid block ID is encountered.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Ubuntu