Heap-based buffer overflow in alsa-lib - CVE-2026-25068
Published: February 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service attack.
The vulnerability exists due to a boundary error within the tplg_decode_control_mixer1() function in src/topology/ctl.c. A remote attacker can pass specially crafted .tplg data to the application, trigger a heap-based buffer overflow and perform a denial of service attack.
Affected software
openEuler
Ubuntu
Anolis OS
alsa-lib (Ubuntu package)
alsa-lib
alsa-lib-debuginfo
alsa-lib-debugsource
alsa-lib-devel
alsa-topology
alsa-ucm
alsa-lib-doc
How to mitigate CVE-2026-25068
alsa-lib - update to 1.2.3-2
alsa-lib-debuginfo - update to 1.2.3-2
alsa-lib-debugsource - update to 1.2.3-2
alsa-lib-devel - update to 1.2.3-2
alsa-topology - update to 1.2.3-2
alsa-ucm - update to 1.2.3-2
alsa-lib - update to 1.2.9-2
alsa-lib-devel - update to 1.2.9-2
alsa-lib-doc - update to 1.2.9-2
alsa-topology - update to 1.2.9-2
alsa-ucm - update to 1.2.9-2