#VU122992 Heap-based buffer overflow in alsa-lib - CVE-2026-25068
Published: February 17, 2026
alsa-lib
Advanced Linux Sound Architecture (ALSA)
Description
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error within the tplg_decode_control_mixer1() function in src/topology/ctl.c. A remote attacker can pass specially crafted .tplg data to the application, trigger a heap-based buffer overflow and perform a denial of service attack.