PT-2026-97360 · Alsa-Lib · Alsa-Lib

CVE-2026-96674

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions alsa-lib versions prior to 1.2.16.2
Description An integer overflow occurs in src/topology/ctl.c when computing the combined topology element size using 32-bit arithmetic. This flaw allows bounds checks to be bypassed. By providing crafted topology files that cause size calculations to wrap, an attacker can force the decoder to read beyond the topology buffer, which may lead to application crashes or the leakage of sensitive data.
Recommendations Update alsa-lib to version 1.2.16.2 or later.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-96674

Affected Products

Alsa-Lib