boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Saturday, October 3, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-64001

Linux Linux — ALSA: pcm: oss: Fix setup list UAF on proc write error
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   L   L   N  U  H  H  H    7.8   .0021   10.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    060d77b9c04acd7aef60790398a53f731db8c8fe –  —
  Linux    2.6.17 –                                    6.12.93
TIMELINE
  Jul 19  Reserved by Linux
  Jul 19  Published (CNA: Linux)
  Oct 2   ENRICHED — CVE-2026-64001 (Linux). Received CVSS 7.8 and CPE data from NVD.
CWE-416 · CNA: Linux · CVSS v3.1 · 4 references · NVD status: Analyzed

Description

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix setup list UAF on proc write error snd_pcm_oss_proc_write() links a newly allocated setup entry into the OSS setup list before duplicating the task name. If the task-name allocation fails, the error path frees the already linked entry and leaves setup_list pointing at freed memory. A later OSS device open can then walk the stale list entry in snd_pcm_oss_look_for_setup() and dereference freed memory. Allocate the task name and initialize the setup entry before publishing the entry on setup_list. Also fetch the initial proc read iterator only after taking setup_mutex, so all setup_list traversal follows the same list lifetime rules.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
July 19, 2026ReservedReserved by Linux
July 19, 2026PublishedPublished (CNA: Linux)
October 2, 2026ENRICHEDENRICHED — CVE-2026-64001 (Linux). Received CVSS 7.8 and CPE data from NVD.

Affected

Affected products and packages — 2 rows
VendorProduct / PackageEcosystemVersion introducedFixed
LinuxLinux—060d77b9c04acd7aef60790398a53f731db8c8fe—
LinuxLinux—2.6.176.12.93

Weaknesses

CWE-416

References (4)

Related

Authoritative record: CVE-2026-64001 at cve.org

Vendors: linux

Weaknesses: CWE-416

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-64001 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Saturday, October 3, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.