CVE-2026-90060: Linux
EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: ALSA: control: Don't add invalid kcontrols to LED layer The kcontrol LED state layer tries to track the all associated kcontrol elements with naive assumptions that they are readable. But one can create a write-only element that has no get callback (even a user element can do it), and this may lead to a NULL dereference at the call chain of snd_ctl_led_notify(), as found by syzkaller. For avoiding the Oops, add a sanity check of the kcontrol's info and get callbacks, and just skip the invalid kcontrols before assigning the kctl to the LED layer.
Affected products
- Linux Linux: from 5.13, before 6.1.188 (fixed in 6.1.188); from 6.2, before 6.12.110 (fixed in 6.12.110); from 6.13, before 6.18.52 (fixed in 6.18.52); from 6.19, before 7.2.6 (fixed in 7.2.6)
Published 2026-09-17. Last modified 2026-09-17.