rootpwn

medium · CVSS v3 3.3 · CVSS v4 4.8

CVE-2026-96675

alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate spar…

Description

alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort.

Scores

Severity
medium
CVSS v2
1.7
CVSS v3
3.3
CVSS v4
4.8
EPSS

← All CVEs