CVE-2026-90781: alsa-lib through 1.2.16.1 Off-by-One Stack Buffer Overflow in __snd_ctl_ascii_elem_id_parse()

Published Sep 13, 2026
·
Updated

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the sndctlasciielemidparse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.

Affected Software

1 affected component
ALSA Project alsa-lib<=1.2.16.1

Event History

Sep 13, 2026
CVE Published
via MITRE·12:22 PM
Data Sourced
via MITRE·12:22 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can realistically exploit this issue?

A local attacker with low privileges who can cause a program using alsa-lib to parse a control-element identifier can trigger it. Relevant input paths include saved state files and command-line arguments.

2

What input triggers the overflow?

The vulnerable parser is triggered by a name= field containing 64 or more characters. It writes one byte past a 64-byte stack buffer while parsing that field.

3

What is the practical impact?

The overflow can overwrite adjacent stack memory and crash the calling process. The supplied severity vector indicates low integrity and availability impact, with no confidentiality impact.

4

What can be done if an update cannot be applied immediately?

Do not allow untrusted saved state files or command-line control-element identifiers to reach the parser. Ensure name= values are shorter than 64 characters where those inputs must be accepted.

5

How can I determine whether software is in scope?

Systems using ALSA Project alsa-lib through version 1.2.16.1 are affected when they invoke __snd_ctl_ascii_elem_id_parse() on control-element identifier input. Check whether local workflows parse saved state files or accept such identifiers through command-line arguments.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203