Bug 2539481 (CVE-2026-96674) - CVE-2026-96674 alsa-lib: alsa-lib: Integer Overflow via Crafted Topology Files
Summary: CVE-2026-96674 alsa-lib: alsa-lib: Integer Overflow via Crafted Topology Files
Keywords:
Status: NEW
Alias: CVE-2026-96674
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2539613
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-23 15:41 UTC by OSIDB Bzimport
Modified: 2026-09-23 18:23 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-23 15:41:38 UTC
alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.


Note You need to log in before you can comment on or make changes to this bug.