CVE-2026-96675
Publication date 24 September 2026
Last updated 24 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate sparse binding indices before array access. Attackers can supply a malicious ALSA configuration file with sparse bindings to trigger an out-of-bounds array read and assertion failure, causing the application to abort.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| alsa-lib | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Severity score breakdown
CVSS version:
Base score
4.8 · Medium
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Base score
3.3 · Low
Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-96675
- https://github.com/alsa-project/alsa-lib/pull/527
- https://github.com/alsa-project/alsa-lib
- https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/pcm/pcm_multi.c#L1122-L1131
- https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-denial-of-service-via-pcm-multi