Stack Buffer Overflow in alsa-lib Affects Users
CVE-2026-90781

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90781?

The alsa-lib library up to version 1.2.16.1 is vulnerable to a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function. This vulnerability arises when parsing 'name=' fields that contain 64 or more characters, allowing attackers to provide a long control-element identifier via saved state files or command-line arguments. By doing so, they can manipulate adjacent stack memory, potentially leading to a crash of the calling process and creating avenues for further exploitation. It is crucial for users of alsa-lib to apply available patches to mitigate this risk.

Affected Version(s)

alsa-lib 0 <= 1.2.16.1

alsa-lib f84cd4ced7b36fddb8e4ee24404cf7c091d27020

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.