{"id":"CVE-2026-64001","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix setup list UAF on proc write error\n\nsnd_pcm_oss_proc_write() links a newly allocated setup entry into the\nOSS setup list before duplicating the task…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix setup list UAF on proc write error\n\nsnd_pcm_oss_proc_write() links a newly allocated setup entry into the\nOSS setup list before duplicating the task…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-416"],"vendor":"linux","product":"linux_kernel","affected":["linux_kernel >= 2.6.17, < 6.12.93","linux_kernel >= 6.13, < 6.18.35","linux_kernel >= 6.19, < 7.0.12","linux_kernel = 7.1"],"patched":["linux_kernel 7.0.12"],"published":"2026-07-19","updated":"2026-10-02","sourceUpdated":"2026-10-02T19:56:13.817","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-64001","references":[{"url":"https://git.kernel.org/stable/c/4cc54bdd54b337e77115be5b55577d1c58608eae","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/be387230dc22d870afd0e5d35912b07c2bc323bd","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd"],"epss":0.00209,"epssPercentile":0.09956,"ingestedAt":"2026-10-02T22:33:09.810Z","slug":"CVE-2026-64001","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix setup list UAF on proc write error\n\nsnd_pcm_oss_proc_write() links a newly allocated setup entry into the\nOSS setup list before duplicating the task name. If the task-name\nallocation fails, the error path frees the already linked entry and\nleaves setup_list pointing at freed memory.\n\nA later OSS device open can then walk the stale list entry in\nsnd_pcm_oss_look_for_setup() and dereference freed memory.\n\nAllocate the task name and initialize the setup entry before publishing\nthe entry on setup_list. Also fetch the initial proc read iterator only\nafter taking setup_mutex, so all setup_list traversal follows the same\nlist lifetime rules.\n\n## Affected\n\n- `linux_kernel >= 2.6.17, < 6.12.93`\n- `linux_kernel >= 6.13, < 6.18.35`\n- `linux_kernel >= 6.19, < 7.0.12`\n- `linux_kernel = 7.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `linux_kernel 7.0.12`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}