---
id: CVE-2026-64001
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ALSA: pcm: oss: Fix setup list UAF on proc write error

  snd_pcm_oss_proc_write() links a newly allocated setup entry into the
  OSS setup list before duplicating the task…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  ALSA: pcm: oss: Fix setup list UAF on proc write error

  snd_pcm_oss_proc_write() links a newly allocated setup entry into the
  OSS setup list before duplicating the task…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-416
vendor: linux
product: linux_kernel
affected:
  - 'linux_kernel >= 2.6.17, < 6.12.93'
  - 'linux_kernel >= 6.13, < 6.18.35'
  - 'linux_kernel >= 6.19, < 7.0.12'
  - linux_kernel = 7.1
patched:
  - linux_kernel 7.0.12
published: '2026-07-19'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T19:56:13.817'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-64001'
references:
  - url: 'https://git.kernel.org/stable/c/4cc54bdd54b337e77115be5b55577d1c58608eae'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8be4efd0dc0093eb7a02ad1aac936bca2a1f04ce'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/be387230dc22d870afd0e5d35912b07c2bc323bd'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e13922bb97b4e6f94f8ac02d034f2d4bd65eeb3c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00209
epssPercentile: 0.09956
ingestedAt: '2026-10-02T22:33:09.810Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

ALSA: pcm: oss: Fix setup list UAF on proc write error

snd_pcm_oss_proc_write() links a newly allocated setup entry into the
OSS setup list before duplicating the task name. If the task-name
allocation fails, the error path frees the already linked entry and
leaves setup_list pointing at freed memory.

A later OSS device open can then walk the stale list entry in
snd_pcm_oss_look_for_setup() and dereference freed memory.

Allocate the task name and initialize the setup entry before publishing
the entry on setup_list. Also fetch the initial proc read iterator only
after taking setup_mutex, so all setup_list traversal follows the same
list lifetime rules.

## Affected

- `linux_kernel >= 2.6.17, < 6.12.93`
- `linux_kernel >= 6.13, < 6.18.35`
- `linux_kernel >= 6.19, < 7.0.12`
- `linux_kernel = 7.1`

## Remediation

Upgrade past the affected range:

- `linux_kernel 7.0.12`
