CVE-2026-98086 | Linux Kernel up to 6.12.110/6.18.52/7.2.6/7.3-rc1 ALSA UMP snd_ump_parse_endpoint/ump_handle_ep_name_msg parsed/legacy_rmidi null pointer dereference

SecurityVulns

A vulnerability, which was classified as critical, was found in Linux Kernel up to 6.12.110/6.18.52/7.2.6/7.3-rc1. This affects the function snd_ump_parse_endpoint/ump_handle_ep_name_msg of the component ALSA UMP. The manipulation of the argument parsed/legacy_rmidi results in null pointer dereference.

This vulnerability is identified as CVE-2026-98086. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More