Integer Overflow Vulnerability in alsa-lib by ALSA Project
CVE-2026-96674

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-96674?

The alsa-lib library up to version 1.2.16.1 contains an integer overflow vulnerability due to inadequate handling of combined topology element size using 32-bit arithmetic. This flaw is present in the source file 'src/topology/ctl.c', where crafted topology files can manipulate size calculations. If exploited, attackers can cause the decoder to read beyond the allocated topology buffer, leading to potential information leakage of sensitive data or application crashes.

Affected Version(s)

alsa-lib 0 <= 1.2.16.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.