GHSA-6634-rq92-25wmunknown

In the Linux kernel, the following vulnerability has been resolved: ALSA: ymfpci: check...

Published
July 25, 2026
Last Modified
July 25, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: ymfpci: check snd_ctl_new1() return value

snd_ctl_new1() can return NULL when memory allocation fails. snd_ymfpci_create_spdif_controls() does not check the return value before dereferencing kctl->id.device, which can lead to a NULL pointer dereference.

Add NULL checks after snd_ctl_new1() calls and return -ENOMEM if any fails.

🔗 References (8)