Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-64479

Published Jul 25, 2026 EPSS 0.18% (8th pctl)

Overview

CVE-2026-64479 is a known-severity vulnerability. It was published on July 25, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup()

snd_seq_event_dup() copies an incoming event into a pool cell and, in

the UMP-enabled build, clears the trailing cell->ump.raw.extra word that

the memcpy() did not cover. The guard deciding whether to clear it

compares the copied size against sizeof(cell->event):

memcpy(&cell->ump, event, size);

if (size < sizeof(cell->event))

cell->ump.raw.extra = 0;

For a legacy (non-UMP) event, size == sizeof(struct snd_seq_event) ==

sizeof(cell->event), so the condition is false and the extra word keeps

stale data. The cell pool is allocated with kvmalloc() (not zeroed) and

cells are reused via a free list, so that word holds uninitialised heap

or leftover event data.

When such a cell is delivered to a UMP client (client->midi_version > 0)

that set SNDRV_SEQ_FILTER_NO_CONVERT -- so the legacy event reaches it

unconverted -- snd_seq_read() reads it out as the l

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-64479?

CVE-2026-64479 is a known-severity vulnerability. It was published on July 25, 2026.

How severe is CVE-2026-64479?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-64479?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-64479?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-64479 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.