Impact
The vulnerability is caused by an off‑by‑one write that overflows a 64‑byte stack buffer in the __snd_ctl_ascii_elem_id_parse() function, allowing an attacker to overwrite adjacent stack memory. This can lead to a crash or, in worse cases, memory corruption. The flaw is identified as CWE‑120 and CWE‑193, indicating a buffer overflow and an off‑by‑one error in buffer handling.
Affected Systems
ALSA Project’s alsa‑lib versions up to and including 1.2.16.1 are affected. Systems that load control elements from saved state files or accept command‑line arguments containing control‑element identifiers are vulnerable. Any installation that has not yet upgraded beyond 1.2.16.1 remains at risk.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score is less than 1% and the issue is not listed in can trigger the overflow by supplying a control‑element identifier string with 64 or more characters through a state file or a command‑line argument. The one‑byte overflow may corrupt adjacent memory and cause the process to crash, though no remote code execution or privilege escalation has been documented.
OpenCVE Enrichment