PT-2026-97360 · Alsa-Lib · Alsa-Lib
CVE-2026-96674
·
Published
2026-09-23
·
Updated
2026-09-23
CVSS v3.1
4.4
Medium
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
alsa-lib versions prior to 1.2.16.2
Description
An integer overflow occurs in src/topology/ctl.c when computing the combined topology element size using 32-bit arithmetic. This flaw allows bounds checks to be bypassed. By providing crafted topology files that cause size calculations to wrap, an attacker can force the decoder to read beyond the topology buffer, which may lead to application crashes or the leakage of sensitive data.
Recommendations
Update alsa-lib to version 1.2.16.2 or later.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alsa-Lib