Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90781

Опубликовано: 13 сент. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.

A flaw was found in alsa-lib. This vulnerability is an off-by-one stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function. A local attacker can exploit this by supplying a specially crafted, long control-element identifier string through saved state files or command-line arguments. This can cause the application to write one byte past a 64-byte buffer, leading to adjacent stack memory corruption and a crash of the calling process, resulting in a Denial of Service (DoS).

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10alsa-libFix deferred
Red Hat Enterprise Linux 6alsa-libOut of support scope
Red Hat Enterprise Linux 7alsa-libFix deferred
Red Hat Enterprise Linux 8alsa-libFix deferred
Red Hat Enterprise Linux 9alsa-libFix deferred
Red Hat Hardened Imagesalsa-libAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2532707alsa-lib: alsa-lib: Denial of Service via off-by-one stack buffer overflow

EPSS

Процентиль: 8%
0.00179
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.4
ubuntu
4 дня назад

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.

CVSS3: 4.4
nvd
4 дня назад

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.

CVSS3: 4.4
debian
4 дня назад

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __sn ...

CVSS3: 4.4
github
4 дня назад

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.

CVSS3: 4.4
fstec
19 дней назад

Уязвимость функции __snd_ctl_ascii_elem_id_parse() библиотеки для взаимодействия со звуковыми драйверами ядра Alsa-lib, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 8%
0.00179
Низкий

6.1 Medium

CVSS3