PT-2026-54644 · Unknown+3 · Pulseaudio+3

·

CVE-2026-14330

·

Published

2026-07-01

·

Updated

2026-08-31

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions PulseAudio (affected versions not specified)
Description The PulseAudio protocol server contains multiple unbounded alloca() calls. The alloca() function allocates memory on the stack, and when these calls are unbounded, they can lead to stack exhaustion.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61240
AZL-92012
CVE-2026-14330
ECHO-47F1-73FB-7E9F
USN-8535-1

Affected Products

Linuxmint
Pulseaudio
Rocky Linux
Ubuntu