Stack Buffer Overflow in alsa-lib Affects Users
CVE-2026-90781
4.8MEDIUM
What is CVE-2026-90781?
The alsa-lib library up to version 1.2.16.1 is vulnerable to a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function. This vulnerability arises when parsing 'name=' fields that contain 64 or more characters, allowing attackers to provide a long control-element identifier via saved state files or command-line arguments. By doing so, they can manipulate adjacent stack memory, potentially leading to a crash of the calling process and creating avenues for further exploitation. It is crucial for users of alsa-lib to apply available patches to mitigate this risk.
Affected Version(s)
alsa-lib 0 <= 1.2.16.1
alsa-lib f84cd4ced7b36fddb8e4ee24404cf7c091d27020
