CVE-2026-64490
説明
A flaw was found in the Linux kernel's ALSA virtio sound driver. A malicious or buggy virtio device can provide invalid control metadata, such as an unknown control type or an oversized value count. The driver's control handling trusts this unvalidated metadata, leading to out-of-bounds access when processing sound control information. This vulnerability could allow a malicious device to cause a denial of service or potentially other impacts on the system.
詳細
ALSA virtio control handling trusted control metadata returned by the virtio-snd device without sufficiently validating the control type and value count. An invalid control type can cause an out-of-bounds index into g_v2a_type_map[], while an oversized value count can drive loops and memcpy() operations beyond the bounds of the fixed-size virtio_snd_ctl_value and snd_ctl_elem_value arrays. This represents a device-to-guest attack surface rather than a network- or packet-reachable vulnerability.
Exploitation requires control over a virtio-snd device or its backend in order to provide crafted control metadata to the guest kernel. An ordinary unprivileged local user inside the guest cannot directly supply the required malicious metadata through normal ALSA interfaces. This significantly restricts the practical attack surface and requires a specially controlled or compromised virtualization environment.
Although the CVSS score is 7.0, these exploitation prerequisites justify rating the issue as Moderate. A malicious or compromised virtio-snd device can trigger out-of-bounds kernel memory accesses and at minimum cause a guest kernel crash, resulting in denial of service. Confidentiality and integrity impacts may also be possible because attacker-controlled metadata is used in operations involving fixed-size kernel buffers. However, exploitation beyond denial of service has not been demonstrated.
軽減策
To mitigate this issue, prevent module virtio_snd from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
CVSS (Common Vulnerability Scoring System) のスコアの詳細
Info alert:Important note
CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).
CVSS v3 スコアの内訳
| Red Hat | NVD | cve.org | |
|---|---|---|---|
| ベーススコア | 7 | N/A | 8.4 |
| 攻撃ベクトル | Local | N/A | Local |
| 攻撃の複雑さ | High | N/A | Low |
| 必要な権限 | Low | N/A | None |
| ユーザー関与レベル | None | N/A | None |
| 範囲 | Unchanged | N/A | Unchanged |
| 機密性 | High | N/A | High |
| 完全性への影響 | High | N/A | High |
| 可用性への影響 | High | N/A | High |
ベクトル
Red Hat: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
cve.org: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
脆弱性の原因 (CWE) の理解
Integrity
Technical Impact: Modify Memory; Execute Unauthorized Code or Commands
Write operations could cause memory corruption. In some cases, an adversary can modify control data such as return addresses in order to execute unexpected code.
Availability
Technical Impact: DoS: Crash, Exit, or Restart
Attempting to access out-of-range, invalid, or unauthorized memory could cause the product to crash.
Other
Technical Impact: Unexpected State
Subsequent write operations can produce undefined or unexpected results.
よくある質問
Not sure what something means? Check out our Security Glossary.
エラータ通知の受信を希望しますか? こちらで登録してください。