CVE-2026-64133

Kernel-memory disclosure via unchecked control index

Published Jul 19, 2026 · Updated Jul 19, 2026

Out-of-bounds read in Linux Kernel ALSA asihpi allows local users to expose kernel memory through a crafted control request. The find_control() function uses an unvalidated control index to access the p_info cache array before later handlers dereference the selected entry. Reachability requires the asihpi driver and a populated control cache; the published behavior supports disclosure and service interruption, not confirmed privilege escalation.

CVSS severity7.8
High
EPSS probability0.13%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Out-of-bounds read in Linux Kernel ALSA asihpi allows local users to expose kernel memory through a crafted control request. The find_control() function uses an unvalidated control index to access the p_info cache array before later handlers dereference the selected entry. Reachability requires the asihpi driver and a populated control cache; the published behavior supports disclosure and service interruption, not confirmed privilege escalation.

The record

CVE
CVE-2026-64133
Published
Jul 19, 2026
Updated
Jul 19, 2026
Vendor
The Linux Kernel Organization
Product
Linux Kernel
Classifications
CWE-125
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Jul 19, 2026CVE publishedPublication date reported by the CVE source.
  2. Jul 19, 2026Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <5.10.258
  2. Affected versionversion=0 <5.15.209
  3. Affected versionversion=0 <6.1.175
  4. Affected versionversion=0 <6.12.92
  5. Affected versionversion=0 <6.18.34
  6. Affected versionversion=0 <6.6.142
  7. Affected versionversion=0 <7.0.11
  8. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <34d0d492a2812b9289af14bca3573a89275965b2
  9. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <61c5017c64e2ac9e10b70b14b17a079dbc0a805f
  10. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7b6f8c8eb93f02a74b1de8e521c0952af10d1f43
  11. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7b7d6572145c1dab2dd9bfb550b188e5f0ff3c3f
  12. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7d107239935793995bdc6cf29bb99e180bde4c28
  13. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <8778386e4387b28f2bf8425d7ffc667c6294457f
  14. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e060e21fe9cca1e5eafd8a1c597026577771e8d9
  15. Affected versionversion=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ffa29cea7bf9a4ef2ea8084967f142e0301ac670

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

The Linux Kernel Organization · Linux Kernelversion=0 <5.10.258; version=0 <5.15.209; version=0 <6.1.175; version=0 <6.12.92; version=0 <6.18.34; version=0 <6.6.142; version=0 <7.0.11; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <34d0d492a2812b9289af14bca3573a89275965b2; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <61c5017c64e2ac9e10b70b14b17a079dbc0a805f; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7b6f8c8eb93f02a74b1de8e521c0952af10d1f43; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7b7d6572145c1dab2dd9bfb550b188e5f0ff3c3f; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <7d107239935793995bdc6cf29bb99e180bde4c28; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <8778386e4387b28f2bf8425d7ffc667c6294457f; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <e060e21fe9cca1e5eafd8a1c597026577771e8d9; version=1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 <ffa29cea7bf9a4ef2ea8084967f142e0301ac670

Published CVSS scores

7.8kernel.orgCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-125Out-of-bounds Read

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo