Описание
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.
A flaw was found in the ALSA (Advanced Linux Sound Architecture) library. This double-free vulnerability, located in the parse_def() function, allows a local attacker to corrupt memory by providing specially crafted ALSA configuration text. When processing nested configuration blocks, the library attempts to free an already freed memory node. This can lead to system instability, crashes, or a denial of service (DoS).
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | alsa-lib | Fix deferred | ||
| Red Hat Enterprise Linux 6 | alsa-lib | Out of support scope | ||
| Red Hat Enterprise Linux 7 | alsa-lib | Fix deferred | ||
| Red Hat Enterprise Linux 8 | alsa-lib | Fix deferred | ||
| Red Hat Enterprise Linux 9 | alsa-lib | Fix deferred | ||
| Red Hat Hardened Images | alsa-lib-main-1.2.16.1-2.hum1 | Fixed | RHSA-2026:40573 | 16.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
6.8 Medium
CVSS3
Связанные уязвимости
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 c ...
EPSS
6.8 Medium
CVSS3