CVE-2026-64487: ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
Published Jul 25, 2026
·Updated
ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser
Affected Software
2 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.144.1-1<6.6.145.2-1
6.6.145.2-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1
Event History
Jul 25, 2026
CVE Published
via MITRE·08:51 AM
Data Sourced
via MITRE·08:51 AM
Description
Data Sourced
via NVD·10:17 AM
Description
Jul 26, 2026
Data Sourced
via Microsoft·08:09 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:09 AM
Affected Software
Updated
via Microsoft·08:09 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-64487?
CVE-2026-64487 has a risk rating of 15, indicating a high severity vulnerability.
2
What kind of vulnerability is CVE-2026-64487?
CVE-2026-64487 is an out-of-bounds read vulnerability in the ALSA caiaq driver for the Traktor Kontrol S4.
3
How do I fix CVE-2026-64487?
To mitigate CVE-2026-64487, it is recommended to update to the latest patched version of the Linux kernel where the vulnerability has been resolved.
4
Which systems are affected by CVE-2026-64487?
CVE-2026-64487 affects Linux kernel systems that utilize the ALSA caiaq driver specifically for the Traktor Kontrol S4.
5
When was CVE-2026-64487 published?
CVE-2026-64487 was published on July 25, 2026.