Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-25068

Опубликовано: 29 янв. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий

Описание

alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.

РелизСтатусПримечание
devel

released

1.2.15.3-1ubuntu1
esm-infra-legacy/trusty

not-affected

code not present
esm-infra-legacy/xenial

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

released

1.2.2-2.1ubuntu2.5+esm1
esm-infra/xenial

not-affected

code not present
jammy

released

1.2.6.1-1ubuntu1.1
noble

released

1.2.11-1ubuntu0.2
questing

released

1.2.14-1ubuntu1.1
resolute

released

1.2.15.3-1ubuntu1

Показывать по

EPSS

Процентиль: 9%
0.00191
Низкий

Связанные уязвимости

CVSS3: 4.3
redhat
6 месяцев назад

alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.

nvd
6 месяцев назад

alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.

debian
6 месяцев назад

alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit ...

github
6 месяцев назад

alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.

CVSS3: 4.3
fstec
6 месяцев назад

Уязвимость функции tplg_decode_control_mixer1 библиотеки для взаимодействия со звуковыми драйверами ядра Alsa-lib, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 9%
0.00191
Низкий