CVE-2026-90781
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
13/09/2026
Last modified:
24/09/2026
Description
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
Impact
Base Score 4.0
4.80
Severity 4.0
MEDIUM
Base Score 3.x
4.40
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/alsa-project/alsa-lib
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241
- https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020
- https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/
- https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse


