CVE-2026-64478
CVE CVE-2026-64478EUVD EUVD-2026-48822Published 2026-07-25T08:51:40.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: avoid kobject path lookup in DualSense match The DualSense jack-detection input handler verifies that a matching input device belongs to the same physical controller by building kobject path strings for both the input device and the USB audio device, then comparing the path prefix. This was observed when a weak physical connection caused the controller to rapidly disconnect and reconnect. During that repeated hotplug, snd_dualsense_ih_match() can run while the controller's USB device is being disconnected. kobject_get_path() walks ancestor kobjects and dereferences their names; if the USB device kobject name is no longer valid, this can fault in strlen(): RIP: 0010:strlen+0x10/0x30 Call Trace: kobject_get_path+0x34/0x150 snd_dualsense_ih_match+0x49/0xd0 [snd_usb_audio] input_register_device+0x566/0x6a0 ps_probe+0xb89/0x1590 [hid_playstation] The same ownership check can be done without building kobject path strings. The input device is parented below the HID device, USB interface and USB device, so walking the input device parent chain and comparing against the mixer USB device preserves the check without dereferencing kobject names during disconnect.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 5.10.245 <5.10.261; patch: 0; d04d301614630724feb4048bf17432fc7964fe74 <a47ecd904c51ae6a42957feb3cf2f4266adee2e5; patch: 6.6.145; patch: 7.2-rc1; patch: 5.10.261; 6.6.109 <6.6.145; 5.4.300 <5.5; a705899ec6085b12a33aa0fd94a58e82e9e90502 <c1da6d3f45036fa63672ee04ad97cb526b40b987; patch: 6.12.96; 6.16.10 <6.17; 79d561c4ec0497669f19a9550cfb74812f60938b <a263eb12cbe2e208e6e637df0f9b0be9a484158e; patch: 5.15.212; patch: 6.1.178; d0b0264009596c07a77d82808b0dae72bc04ac5c <e4c66a149c408e44e60bfec3fabf08b6b7abbc60; c2d5b0a6c688ffb32c35627e337fbbcc65bc275f <662a1d7b5affc424ea4f4bc20dd99be29e687886; patch: 7.1.4; b4b94f092f193d7a2db8e82af5e51519ae89963c <4566bf8ae9dbfe81bdc2ff1702d59db8a233b06e; 6.1.155 <6.1.178; 0105cfc41abeb428d4405951a20e1e239bea5e1d; 79d561c4ec0497669f19a9550cfb74812f60938b <4246dd043b7a4f8e3bc1d2896e81d11220610eda; 79d561c4ec0497669f19a9550cfb74812f60938b <7693c0cc415f3a16a7a3355f245474a5e661be4e; 104ad9bae11ee450fb7d0595ff7876cfb6527838; patch: 6.18.39; 6.17; 5.15.194 <5.15.212; 6.12.50 <6.12.96
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.