CVE-2026-96674
4.4 MEDIUMpublic exploit availablePublished 2026-09-23 · Updated 2026-09-24
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Weaknesses
CWE-190
Public exploit & PoC references
- https://github.com/alsa-project/alsa-lib
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521
- https://github.com/alsa-project/alsa-lib/pull/527
All references
- https://github.com/alsa-project/alsa-lib
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521
- https://github.com/alsa-project/alsa-lib/pull/527
- https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-14181PoC
- HIGHCVE-2026-100208
- MEDIUMCVE-2026-101279
- LOWCVE-2026-102620PoC
- LOWCVE-2026-102621PoC
- MEDIUMCVE-2026-102633PoC
- MEDIUMCVE-2026-102804PoC
- MEDIUMCVE-2026-102805PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.