CVE-2026-25068

Publication date 29 January 2026

Last updated 9 June 2026


Ubuntu priority

Description

alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplg_decode_control_mixer1() function reads the num_channels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive num_channels value can cause out-of-bounds heap writes, leading to a crash.

Status

Package Ubuntu Release Status
alsa-lib 26.04 LTS resolute
Fixed 1.2.15.3-1ubuntu1
25.10 questing
Fixed 1.2.14-1ubuntu1.1
24.04 LTS noble
Fixed 1.2.11-1ubuntu0.2
22.04 LTS jammy
Fixed 1.2.6.1-1ubuntu1.1
20.04 LTS focal
Fixed 1.2.2-2.1ubuntu2.5+esm1
18.04 LTS bionic
Not affected
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro 30-day free trial

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
alsa-lib

Severity score breakdown

CVSS version: CVSS v4.0

Base score 4.6 · Medium

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

References

Related Ubuntu Security Notices (USN)

Other references


Access our resources on patching vulnerabilities