{"id":"CVE-2026-90781","title":"alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters","summary":"alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long cont…","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-193","CWE-120"],"vendor":"ALSA Project","product":"alsa-lib","affected":["alsa-lib <= 1.2.16.1"],"published":"2026-09-13","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:18:43.543","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90781","references":[{"url":"https://github.com/alsa-project/alsa-lib","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020","label":"disclosure@vulncheck.com"},{"url":"https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse","label":"disclosure@vulncheck.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90781.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-90781"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2532707"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-90781"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90781"},{"url":"https://access.redhat.com/errata/RHSA-2026:67289"},{"url":"https://access.redhat.com/errata/RHSA-2026:40573"}],"tags":["nvd","exploit-available","cve.org","csaf","vex","red-hat"],"epss":0.00179,"epssPercentile":0.0769,"exploits":{"github":1,"githubRepos":["https://github.com/HarshRajSinghania/CVE-2026-90781-alsa-lib-oob"],"checkedAt":"2026-09-21T15:31:24.639Z"},"exploitAvailable":true,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-16T14:07:32.254861Z"},"scores":{"nvd":4.4,"cna":4.4,"vendor":6.1},"ingestedAt":"2026-09-14T15:23:07.470Z","patched":["hardened_images"],"slug":"CVE-2026-90781","body":"## Overview\n\nalsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90781.json)\n- **RHSA-2026:67289** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67289)\n- **RHSA-2026:40573** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:40573)","depth":"twilight","depthScore":36,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[{"seq":205307,"id":"CVE-2026-90781","ts":1789570707928,"field":"cvss","old":"6.1","new":"4.4"},{"seq":202810,"id":"CVE-2026-90781","ts":1789403728450,"field":"cvss","old":"4.4","new":"6.1"},{"seq":197650,"id":"CVE-2026-90781","ts":1789384317942,"field":"exploit_available","old":"false","new":"true"}]}