#1141309 pulseaudio: CVE-2026-14330

Package:
src:pulseaudio
Source:
src:pulseaudio
Submitter:
Moritz Mühlenhoff
Date:
2026-09-21 09:45:04 UTC
Severity:
normal
Tags:
#1141309#5
Date:
2026-07-02 19:44:51 UTC
From:
To:
Hi,

The following vulnerability was published for pulseaudio.

CVE-2026-14330[0]:
| Multiple unbounded alloca() calls in the PulseAudio protocol server.

https://bugzilla.redhat.com/show_bug.cgi?id=2495907


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14330
https://www.cve.org/CVERecord?id=CVE-2026-14330

Please adjust the affected versions in the BTS as needed.

#1141309#24
Date:
2026-09-18 13:12:18 UTC
From:
To:
Hello,

I have created the following PR that addresses this CVE:
https://salsa.debian.org/utopia-team/pipewire/-/merge_requests/37

It had some conflicts that had to be fixed manually. The origin of the
patch is upstream here:
https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/ed2c0ad4eee1695381e06f7accb902cbcf547420.patch

Since this patch does not seem to be part of any pipewire release yet
according to the freedesktop gitlab webui as well as some git-fu I run
locally to confirm, we cannot fix this problem by simply importing a new
upstream release.

I am also planning to propagate this fix to stable releases and
backports as needed.

Thanks in advance,

Agathe.

#1141309#27
Date:
2026-09-21 07:44:23 UTC
From:
To:
Hello,

Bug #1141309 in pipewire reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/utopia-team/pipewire/-/commit/13ea63cb7af9db40633aa82113352e6ff59d65da
------------------------------------------------------------------------
Import+rebase upstream patch for CVE-2026-14330

Closes: #1141309
Signed-off-by: Agathe Porte <agathe.porte@oss.qualcomm.com>
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1141309

#1141309#34
Date:
2026-09-21 09:44:04 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
pipewire, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1141309@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Dylan Aïssi <daissi@debian.org> (supplier of updated pipewire package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 21 Sep 2026 10:24:33 +0200
Source: pipewire
Architecture: source
Version: 1.6.9-2
Distribution: unstable
Urgency: medium
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@alioth-lists.debian.net>
Changed-By: Dylan Aïssi <daissi@debian.org>
Closes: 1141309
Changes:
 pipewire (1.6.9-2) unstable; urgency=medium
 .
   [ Agathe Porte ]
   * Import+rebase upstream patch for CVE-2026-14330 (Closes: #1141309)
 .
   [ Dylan Aïssi ]
   * Bump minimum libcamera to 0.6.0
Checksums-Sha1:
 e73db039263c020807043758e05a4cb220c6d9ea 4895 pipewire_1.6.9-2.dsc
 07d6f17a236fb8bbe3e8cae9eb87bb3c11ab0e96 34132 pipewire_1.6.9-2.debian.tar.xz
 34aa5d6eb2fa49843ac1cf3a5c686fe1af1bca5a 29737 pipewire_1.6.9-2_amd64.buildinfo
Checksums-Sha256:
 e5ec430d51f53d5c9f7220cadf2943950c7b1ca3a51eb608ef6e7dbdeb5b5895 4895 pipewire_1.6.9-2.dsc
 9ee24622dfd907c8f1283328632156d43d23013c7ce62b04ea8ed6991a1ae65c 34132 pipewire_1.6.9-2.debian.tar.xz
 3c4c4c3db8ad3f79d2d4e05ea8519b0ff09aacd0cea77921054a9562c2f29542 29737 pipewire_1.6.9-2_amd64.buildinfo
Files:
 69cad48473e1b9cc1578f48752d9058f 4895 libs optional pipewire_1.6.9-2.dsc
 5583f9036e10ee5571183c22a1a1bd36 34132 libs optional pipewire_1.6.9-2.debian.tar.xz
 feb3ad3d47b420302ba3550028cea35c 29737 libs optional pipewire_1.6.9-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEmjwHvQbeL0FugTpdYS7xYT4FD1QFAmqw7AwACgkQYS7xYT4F
D1QEnQ/+ObXmWwu7k0q4FsgOWm+lLs38/pgFCMWDsuAoc0CaitnBl2+amDBBLgXU
eJCnUnOGlB/TSx6rS7v+eNNePUGl4NPg4wbczMmQkb0QEbPBEJgz9Ehe7b9zn0mv
rvqnIlZiHHbmvG13Tr8umFnDgKKTe+vDdFLF7jxrOb9AaMv9x0SQwSjzeQKdt3F/
hAx8Miz4+WxMOYNzhUl1AzSz7iMXDyzRU/R8mI1aibB7wo/+t8FY4g8g0L9toh0M
jnK0LnkVWHH5czsBJ0ziOknq7rVL/r5qQLuVI/ievlEmLQjhu1stbXvKivl/evzs
g+ew6L5egn5P5bIJkAPvAa9lTmZHrJLpLxXiq64qqlJb+VW+rEIj2PwsUu2KxTfa
Y2BYqSL/MRj6Jzcz0XZsf+lf3641E0n66CG77MPFmOU9rwOH73iFa53T1nry5lHy
20zPKXuaGDar9WYR7IRx58O5F6YgS688t1DUVV6lybFBSXFSj62IG0tJChpJLWCH
wM/Nyva+kaN/Lp7oKDx+iBAGZSZ9KvsQdMryWcHJTKLYBOixMTHCpGdqYcxPzCY0
DNsb+seyqZHB6VwlBXrFN1si2NR3O856yI0t8TKfsn3flkkDY3nDW6QFre6YnnNk
MxJ2zgYDOFJZKXGFc/IT3yRgx7+xH6TvYfPrMGZBB+fhDpesepQ=
=/2l7
-----END PGP SIGNATURE-----