Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4469-1 | alsa-lib security update |
Ubuntu USN |
USN-8044-1 | alsa-lib vulnerability |
Thu, 05 Mar 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:* |
Fri, 06 Feb 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 30 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Alsa-project
Alsa-project alsa-lib |
|
| Vendors & Products |
Alsa-project
Alsa-project alsa-lib |
Fri, 30 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 29 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Jan 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash. | |
| Title | alsa-lib 1.2.15.2 Topology Decoder Heap-based Buffer Overflow | |
| Weaknesses | CWE-129 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-11T23:11:05.236Z
Reserved: 2026-01-28T21:47:35.120Z
Link: CVE-2026-25068
Updated: 2026-02-06T00:15:45.511Z
Status : Deferred
Published: 2026-01-29T20:16:10.623
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-25068
OpenCVE Enrichment
Updated: 2026-04-16T17:45:27Z
Debian DLA
Ubuntu USN