Heap-Based Buffer Overflow in alsa-lib by the ALSA Project
CVE-2026-25068
4.6MEDIUM
What is CVE-2026-25068?
The alsa-lib library versions 1.2.2 through 1.2.15.2 are affected by a heap-based buffer overflow due to improper handling of untrusted topology files. Specifically, the tplg_decode_control_mixer1() function fails to validate the num_channels field before using it to define loop boundaries. This oversight can lead to out-of-bounds heap writes, potentially causing application crashes when processing manipulated topology data. Users should consider implementing patches to secure their systems against this vulnerability.
Affected Version(s)
alsa-lib 1.2.2 <= 1.2.15.2
alsa-lib 5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40
References
CVSS V4
Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Sajeeb Lohani (sml555 / prodigysml)
VulnCheck
