Description
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
Published: 2026-09-13
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stack Buffer Overflow leading to process crash
Action: Patch
AI Analysis

Impact

The vulnerability is caused by an off‑by‑one write that overflows a 64‑byte stack buffer in the __snd_ctl_ascii_elem_id_parse() function, allowing an attacker to overwrite adjacent stack memory. This can lead to a crash or, in worse cases, memory corruption. The flaw is identified as CWE‑120 and CWE‑193, indicating a buffer overflow and an off‑by‑one error in buffer handling.

Affected Systems

ALSA Project’s alsa‑lib versions up to and including 1.2.16.1 are affected. Systems that load control elements from saved state files or accept command‑line arguments containing control‑element identifiers are vulnerable. Any installation that has not yet upgraded beyond 1.2.16.1 remains at risk.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score is less than 1% and the issue is not listed in can trigger the overflow by supplying a control‑element identifier string with 64 or more characters through a state file or a command‑line argument. The one‑byte overflow may corrupt adjacent memory and cause the process to crash, though no remote code execution or privilege escalation has been documented.

Generated by OpenCVE AI on September 15, 2026 at 16:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade alsa‑lib to the latest available version that includes the fix.
  • Prevent passing control‑element identifiers longer than 63 characters when configuring ALSA; validate or truncate input strings.
  • Restart any services using the library after applying the update to clear any corrupted state.

Generated by OpenCVE AI on September 15, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Moderate


Sun, 13 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.
Title alsa-lib through 1.2.16.1 Off-by-One Stack Buffer Overflow in __snd_ctl_ascii_elem_id_parse()
First Time appeared Alsa-project
Alsa-project alsa-lib
Weaknesses CWE-193
CPEs cpe:2.3:a:alsa-project:alsa-lib:*:*:*:*:*:*:*:*
Vendors & Products Alsa-project
Alsa-project alsa-lib
References
Metrics cvssV3_1

{'score': 4.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Alsa-project Alsa-lib
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T14:07:43.295Z

Reserved: 2026-09-13T12:01:26.987Z

Link: CVE-2026-90781

cve-icon Vulnrichment

Updated: 2026-09-16T14:07:38.073Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T13:16:29.263

Modified: 2026-09-24T20:47:31.797

Link: CVE-2026-90781

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-13T12:22:01Z

Links: CVE-2026-90781 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-193

    Off-by-one Error