CVE Database
/

CVE-2026-25068

Back to search

CVE-2026-25068

Published: Jan 29, 2026

Modified: May 25, 2026

PUBLISHED

Description

alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.

VendorProductVersions

ALSA Project

alsa-lib

affected
1.2.2 - <= 1.2.15.2
unaffected
5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now