A vulnerability was found in Linux Kernel up to 6.12.95/6.18.38/7.1.3. It has been classified as very critical. Affected is the function
virtsnd_kctl_parse_cfg of the component ALSA. Performing a manipulation results in out-of-bounds read.
This vulnerability was named CVE-2026-64490. The attack needs to be approached locally. There is no available exploit.
Upgrading the affected component is recommended.