PT-2026-51365 · Alsa · Alsa-Lib

Dmitrijs Trizna

+3

·

Publicado

2026-06-22

·

Atualizado

2026-06-22

·

CVE-2026-56109

CVSS v3.1

6.8

Média

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse def() fails to check return values before continuing, causing snd config delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.

Exploit

Correção

Double Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-56109

Produtos afetados

Alsa-Lib