medium · CVSS v3 3.3 · CVSS v4 4.8
CVE-2026-96675
alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate spar…
Description
alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort.
Scores
- Severity
- medium
- CVSS v2
- 1.7
- CVSS v3
- 3.3
- CVSS v4
- 4.8
- EPSS
- —