---
id: CVE-2026-90781
title: >-
  alsa-lib through 1.2.16.1 contains a stack buffer overflow in the
  __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte
  buffer when parsing a name= field with 64 or more characters
summary: >-
  alsa-lib through 1.2.16.1 contains a stack buffer overflow in the
  __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte
  buffer when parsing a name= field with 64 or more characters. Attackers can
  supply a long cont…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-193
  - CWE-120
vendor: ALSA Project
product: alsa-lib
affected:
  - alsa-lib <= 1.2.16.1
patched:
  - hardened_images
published: '2026-09-13'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T20:47:31.797'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90781'
references:
  - url: 'https://github.com/alsa-project/alsa-lib'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/control/ctlparse.c#L216-L241
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020
    label: disclosure@vulncheck.com
  - url: >-
      https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-off-by-one-stack-buffer-overflow-in-snd-ctl-ascii-elem-id-parse
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90781.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-90781'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2532707'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-90781'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90781'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67289'
  - url: 'https://access.redhat.com/errata/RHSA-2026:40573'
tags:
  - nvd
  - exploit-available
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.0017
epssPercentile: 0.05601
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/HarshRajSinghania/CVE-2026-90781-alsa-lib-oob'
  checkedAt: '2026-09-24T20:52:15.418Z'
exploitAvailable: true
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-16T14:07:32.254861Z'
scores:
  nvd: 4.4
  cna: 4.4
  vendor: 6.1
ingestedAt: '2026-09-14T15:23:07.470Z'
---

## Overview

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite adjacent stack memory and crash the calling process.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-90781.json)
- **RHSA-2026:67289** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67289)
- **RHSA-2026:40573** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:40573)
