Debian Alsa-Lib vulnerabilities
2 known vulnerabilities affecting debian/alsa-lib.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1LOW1
Vulnerabilities
Page 1 of 1
CVE-2026-25068MEDIUMCVSS 4.6fixed in alsa-lib 1.2.4-1.1+deb11u1 (bullseye)2026
CVE-2026-25068 [MEDIUM] CVE-2026-25068: alsa-lib - alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, c...
alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A cra
debian
CVE-2005-0087LOWCVSS 4.6fixed in alsa-lib 1.0.9-1 (bookworm)2005
CVE-2005-0087 [MEDIUM] CVE-2005-0087: alsa-lib - The alsa-lib package in Red Hat Linux 4 disables stack protection for the libaso...
The alsa-lib package in Red Hat Linux 4 disables stack protection for the libasound.so library, which makes it easier for attackers to execute arbitrary code if there are other vulnerabilities in the library.
Scope: local
bookworm: resolved (fixed in 1.0.9-1)
bullseye: resolved (fixed in 1.0.9-1)
forky: resolved (fixed in 1.0.9-1)
sid: resolved (fixed in 1.0.9-1)
t
debian