Logo
vulnerabilityCVE-2026-56109
Name
CVE-2026-56109
Source
NVD ( link)Debian ( link)
Description
The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
alsa-lib
Exploitable

Vulnerability Ratings#


7
CVSSv4
6.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.2.13
Exploitable
buildroot
master
1.2.16.1
Not Affected
yocto
kirkstone
1.2.6.1
Exploitable
yocto
master
1.2.16.1
Not Affected