GHSA-3gf2-g4r5-8vxrMediumCVSS 3.3
alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that...
🔗 CVE IDs covered (1)
📋 Description
alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-96675
- https://github.com/alsa-project/alsa-lib/pull/527
- https://github.com/alsa-project/alsa-lib
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/pcm/pcm_multi.c#L1122-L1131
- https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-denial-of-service-via-pcm-multi
- https://github.com/advisories/GHSA-3gf2-g4r5-8vxr