Denial of Service Vulnerability in alsa-lib by ALSA Project
CVE-2026-96675
4.8MEDIUM
What is CVE-2026-96675?
The alsa-lib library, utilized by various applications for audio management, contains a vulnerability within its multi PCM plugin. This vulnerability arises due to insufficient validation of sparse binding indices, which allows attackers to create malicious ALSA configuration files. When these files are processed, they can trigger an out-of-bounds read, leading to an assertion failure in the application and causing it to abort unexpectedly. As a result, this vulnerabilities can result in service disruption for users relying on the alsa-lib library for audio playback and management.
Affected Version(s)
alsa-lib 0 <= 1.2.16.1
