#1147619 alsa-lib: CVE-2026-90781

Package:
src:alsa-lib
Source:
src:alsa-lib
Submitter:
Salvatore Bonaccorso
Date:
2026-09-29 06:21:02 UTC
Severity:
normal
Tags:
#1147619#5
Date:
2026-09-13 21:02:02 UTC
From:
To:
Hi,

The following vulnerability was published for alsa-lib.

CVE-2026-90781[0]:
| alsa-lib through 1.2.16.1 contains a stack buffer overflow in the
| __snd_ctl_ascii_elem_id_parse() function that writes one byte past a
| 64-byte buffer when parsing a name= field with 64 or more
| characters. Attackers can supply a long control-element identifier
| string through saved state files or command-line arguments to
| overwrite adjacent stack memory and crash the calling process.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90781
https://www.cve.org/CVERecord?id=CVE-2026-90781
[1] https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/
[2] https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1147619#16
Date:
2026-09-18 13:43:46 UTC
From:
To:
Hello,

I have created the following PR on salsa to fix this issue:
https://salsa.debian.org/alsa-team/alsa-lib/-/merge_requests/6

Thanks,

Agathe.

#1147619#21
Date:
2026-09-29 06:19:50 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
alsa-lib, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1147619@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jordi Mallach <jordi@debian.org> (supplier of updated alsa-lib package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 29 Sep 2026 07:14:41 +0200
Source: alsa-lib
Architecture: source
Version: 1.2.16.1-2
Distribution: unstable
Urgency: medium
Maintainer: Debian ALSA Maintainers <pkg-alsa-devel@lists.alioth.debian.org>
Changed-By: Jordi Mallach <jordi@debian.org>
Closes: 1147619
Changes:
 alsa-lib (1.2.16.1-2) unstable; urgency=medium
 .
   [ Agathe Porte ]
   * Import upstream patches for CVE-2026-90781 (Closes: #1147619)
Checksums-Sha1:
 de9e4fbc50c019d11ffc802206d396efb8cfd3dc 2939 alsa-lib_1.2.16.1-2.dsc
 718bff41df751482dcd352e3727fd1bc97dc2770 34748 alsa-lib_1.2.16.1-2.debian.tar.xz
 1ddbd060e660f25a7762be0f21958700c9610200 11449 alsa-lib_1.2.16.1-2_amd64.buildinfo
Checksums-Sha256:
 b276460332cb208244b8ca85be2606a4d3bab6423b55f8a155907f8fb5816fa2 2939 alsa-lib_1.2.16.1-2.dsc
 ad24529b3a5d2ac02b2035b7152d3f9cd865268468b59c15faef1920af85ea75 34748 alsa-lib_1.2.16.1-2.debian.tar.xz
 7165f79f84ec6f8ebd2f8c8af0f2477b7ffe9a97508ed18be03980fbe7d9cfae 11449 alsa-lib_1.2.16.1-2_amd64.buildinfo
Files:
 d1ec0e2bcaf329f61197c93cdda4de9b 2939 libs optional alsa-lib_1.2.16.1-2.dsc
 5a7ede443dcd13dd1a151cc7221d0486 34748 libs optional alsa-lib_1.2.16.1-2.debian.tar.xz
 c5902ab17c5874d6142a1e7bf8e1f734 11449 libs optional alsa-lib_1.2.16.1-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE6BdUhsApKYN8KGoWJVAvb8vjywQFAmq7Vf4ACgkQJVAvb8vj
ywRaQBAAiO5rSUJ4pDHBv+kv5X2qi2maybnvpEKWyZ4aH1lorwz6d7iOCmmlHQo8
GC+TsB2ItzitKx0Iix7YqWT4qH8vX/qsZJ3KI4RyZa6JoYsxWiflV9OGpA0SBhnV
zEPtn0DWXFmfyjdHsTMd68QE8srsf0PLtwznS06cgMeGwa9bR6KSCDobg96vVeU8
Dd2KzOsYsQPBEyds12qsHPyPWat0hpzqRYSafDm3CcHBkaVKj6HCV5T18A3I6Scn
X0PGynRYXANfFDeCcr3eKtmIvMdrFXSUcfrR4MKEjpgyOsMtKPvIMTE56My6uNus
cv7dTO0rs33N/IX/FgmGvEqJFlsW9MRhtn7DlpY96BnjJjiZm2Bm8Xw+V8StwHL0
8zut3VYjxSRBtq6MOA3bMWkujz0ljbJ1274mU56GB1i2aBG9wUdtLatNY6GXVbzQ
hhzCn7wSaMskCk+JIexmV3QwZOYdvSNL9ilW3y1Zx31rwqr1mfCGQmX4wsk3bGq2
15YLEjWRFtmarpuWzdDsBP5Obr1HVN6mVjiErUjBgdCbVOjpxieRvPmeL59iFWrD
4P+q1sA8vp94R7CPodbjC2ZKeD4Rcae8oVwWbbozF7seyGOf4MbSjcBdN/jw4d80
Hb+9Jh312bGeXJnBoRzOXNp7F275VZM48aPYnxAWPD/nDYhojhA=
=XD59
-----END PGP SIGNATURE-----