PT-2026-51365 · Alsa · Alsa-Lib

Dmitrijs Trizna

+3

·

Published

2026-06-22

·

Updated

2026-06-22

·

CVE-2026-56109

CVSS v3.1

6.8

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse def() fails to check return values before continuing, causing snd config delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.

Exploit

Fix

Double Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56109

Affected Products

Alsa-Lib