Denial of Service Vulnerability in alsa-lib by ALSA Project
CVE-2026-96675

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
23 September 2026

What is CVE-2026-96675?

The alsa-lib library, utilized by various applications for audio management, contains a vulnerability within its multi PCM plugin. This vulnerability arises due to insufficient validation of sparse binding indices, which allows attackers to create malicious ALSA configuration files. When these files are processed, they can trigger an out-of-bounds read, leading to an assertion failure in the application and causing it to abort unexpectedly. As a result, this vulnerabilities can result in service disruption for users relying on the alsa-lib library for audio playback and management.

Affected Version(s)

alsa-lib 0 <= 1.2.16.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.