{"id":"CVE-2026-96674","title":"alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks","summary":"alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculation…","severity":"medium","cvss":4.4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L","cwe":["CWE-190","CWE-125"],"vendor":"ALSA Project","product":"alsa-lib","affected":["alsa-lib <= 1.2.16.1"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T20:17:26.930","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96674","references":[{"url":"https://github.com/alsa-project/alsa-lib","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521","label":"disclosure@vulncheck.com"},{"url":"https://github.com/alsa-project/alsa-lib/pull/527","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file","label":"disclosure@vulncheck.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-96674.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-96674"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2539481"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-96674"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-96674"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-23T18:13:27.889547Z"},"ingestedAt":"2026-09-23T16:27:22.659Z","slug":"CVE-2026-96674","body":"## Overview\n\nalsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-96674.json)","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":24.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}