---
id: CVE-2026-96674
title: >-
  alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit
  arithmetic in src/topology/ctl.c, allowing integer overflow that defeats
  bounds checks
summary: >-
  alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit
  arithmetic in src/topology/ctl.c, allowing integer overflow that defeats
  bounds checks. Attackers can supply crafted topology files that wrap size
  calculation…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'
cwe:
  - CWE-190
  - CWE-125
vendor: ALSA Project
product: alsa-lib
affected:
  - alsa-lib <= 1.2.16.1
published: '2026-09-23'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:08:55.030'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96674'
references:
  - url: 'https://github.com/alsa-project/alsa-lib'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1316-L1326
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1420-L1430
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/alsa-project/alsa-lib/blob/v1.2.16.1/src/topology/ctl.c#L1511-L1521
    label: disclosure@vulncheck.com
  - url: 'https://github.com/alsa-project/alsa-lib/pull/527'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/alsa-lib-through-1.2.16.1-integer-overflow-via-topology-file
    label: disclosure@vulncheck.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-96674.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-96674'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2539481'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-96674'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96674'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00115
epssPercentile: 0.01396
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T18:13:27.889547Z'
ingestedAt: '2026-09-23T16:27:22.659Z'
---

## Overview

alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowing integer overflow that defeats bounds checks. Attackers can supply crafted topology files that wrap size calculations, causing the decoder to read beyond the topology buffer and potentially leak sensitive data or crash the application.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-96674.json)
