#1148900 alsa-lib: CVE-2026-96675

Package:
src:alsa-lib
Source:
src:alsa-lib
Submitter:
Salvatore Bonaccorso
Date:
2026-09-24 18:47:02 UTC
Severity:
normal
Tags:
#1148900#5
Date:
2026-09-24 18:45:03 UTC
From:
To:
Hi,

The following vulnerability was published for alsa-lib.

CVE-2026-96675[0]:
| alsa-lib through 1.2.16.1 contains a denial of service vulnerability
| in the multi PCM plugin that fails to validate sparse binding
| indices before array access. Attackers can supply a malicious ALSA
| configuration file with sparse bindings to trigger an out-of-bounds
| array read and assertion failure, causing the application to abort.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-96675
https://www.cve.org/CVERecord?id=CVE-2026-96675

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore