{"id":"CVE-2026-25068","summary":"alsa-lib 1.2.15.2 Topology Decoder Heap-based Buffer Overflow","details":"alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.","modified":"2026-08-12T15:32:57.362563Z","published":"2026-01-29T19:08:03.986Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-129"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25068.json"},"references":[{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2026/02/msg00008.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25068.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25068"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/alsa-lib-topology-decoder-heap-based-buffer-overflow"},{"type":"FIX","url":"https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alsa-project/alsa-lib","events":[{"introduced":"717a8425ff13bac20c94796ca726f5222480f7d5"},{"fixed":"5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"1.2.2"},{"last_affected":"1.2.15.2"}]}}],"versions":["v1.2.15.3","v1.2.15.2","v1.2.15.1","v1.2.15","v1.2.14","v1.2.13","v1.2.12","v1.2.11","v1.2.10","v1.2.9","v1.2.8","v1.2.7.2","v1.2.7.1","v1.2.7","v1.2.6.1","v1.2.6","v1.2.5","v1.2.4","v1.2.3.2","v1.2.3.1","v1.2.3","v1.2.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25068.json","vanir_signatures_modified":"2026-08-12T15:32:57Z","vanir_signatures":[{"source":"https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40","target":{"file":"src/topology/ctl.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["40889492823950341381219997890138818637","215537673880048521820366870348777685505","319064719151019657717276530282089549044","301499185625432265915833169725067162728"]},"id":"CVE-2026-25068-04f3a047","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40","target":{"file":"src/topology/ctl.c","function":"tplg_decode_control_mixer1"},"deprecated":false,"digest":{"function_hash":"207084074088684355095339922975343511881","length":2444},"id":"CVE-2026-25068-0cbbd58c","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}