In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: avoid kobject path lookup in DualSense match The DualSense… (CVE-2026-64478)
A vulnerability in the Linux kernel's ALSA usb-audio driver related to the DualSense jack-detection input handler has been resolved. The issue occurs when the handler attempts to verify device ownership by building kobject path strings during rapid USB device disconnect and reconnect events. This can lead to a fault in strlen() due to dereferencing invalid kobject names. The fix avoids building kobject path strings and instead walks the input device parent chain to perform the ownership check safely.
AI Analysis
Technical Summary
The Linux kernel ALSA usb-audio driver for DualSense devices previously performed ownership verification by constructing kobject path strings for input and USB audio devices and comparing their prefixes. During rapid disconnect and reconnect cycles of the controller, snd_dualsense_ih_match() could execute while the USB device kobject name was invalid, causing a fault in strlen() due to dereferencing freed memory. The vulnerability was addressed by replacing the kobject path string comparison with a safer method that walks the input device's parent chain and compares it to the USB device, eliminating unsafe dereferencing during disconnect.
Potential Impact
The vulnerability could cause a kernel fault (crash) due to dereferencing invalid memory during USB device hotplug events involving the DualSense controller. This may lead to system instability or denial of service. There is no indication of privilege escalation or code execution from the provided data.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to avoid unsafe kobject path lookups in the DualSense jack-detection input handler. Users should update to a Linux kernel version that includes this fix. Patch status is not explicitly stated; check the vendor or Linux kernel advisories for the specific fixed versions and apply updates accordingly.
In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: avoid kobject path lookup in DualSense match The DualSense… (CVE-2026-64478)
Description
A vulnerability in the Linux kernel's ALSA usb-audio driver related to the DualSense jack-detection input handler has been resolved. The issue occurs when the handler attempts to verify device ownership by building kobject path strings during rapid USB device disconnect and reconnect events. This can lead to a fault in strlen() due to dereferencing invalid kobject names. The fix avoids building kobject path strings and instead walks the input device parent chain to perform the ownership check safely.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel ALSA usb-audio driver for DualSense devices previously performed ownership verification by constructing kobject path strings for input and USB audio devices and comparing their prefixes. During rapid disconnect and reconnect cycles of the controller, snd_dualsense_ih_match() could execute while the USB device kobject name was invalid, causing a fault in strlen() due to dereferencing freed memory. The vulnerability was addressed by replacing the kobject path string comparison with a safer method that walks the input device's parent chain and compares it to the USB device, eliminating unsafe dereferencing during disconnect.
Potential Impact
The vulnerability could cause a kernel fault (crash) due to dereferencing invalid memory during USB device hotplug events involving the DualSense controller. This may lead to system instability or denial of service. There is no indication of privilege escalation or code execution from the provided data.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to avoid unsafe kobject path lookups in the DualSense jack-detection input handler. Users should update to a Linux kernel version that includes this fix. Patch status is not explicitly stated; check the vendor or Linux kernel advisories for the specific fixed versions and apply updates accordingly.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-wv3c-4j75-q9c9
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64478"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a6542069c2644c7f808237c
Added to database: 07/25/2026, 23:08:54 UTC
Last enriched: 07/25/2026, 23:16:08 UTC
Last updated: 07/26/2026, 05:44:27 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.