PT-2026-51365 · Unknown+2 · Alsa Library+2

·

CVE-2026-56109

·

Published

2026-06-22

·

Updated

2026-08-04

CVSS v4.0

7.0

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ALSA library versions prior to 1.2.16.1
Description A double-free issue exists in the parse def() function within src/conf.c. This occurs when the system parses nested compound or array configuration blocks and fails to check return values before proceeding. Consequently, the snd config delete() function is called twice on the same already-freed node, which can lead to memory corruption, a NULL-pointer write, or an invalid memory read if an attacker provides maliciously crafted ALSA configuration text.
Recommendations Update ALSA library to version 1.2.16.1.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-90204
CVE-2026-56109
ECHO-00B6-A8A9-0340
OESA-2026-2847
OESA-2026-2848
OESA-2026-2849
OESA-2026-2850
OPENSUSE-SU-2026:21075-1
RHSA-2026:40573
SUSE-SU-2026:22291-1
SUSE-SU-2026:22381-1
SUSE-SU-2026:22667-1
SUSE-SU-2026:2885-1
SUSE-SU-2026:3270-1
SUSE-SU-2026:3492-1
USN-8538-1

Affected Products

Alsa Library
Linuxmint
Ubuntu