rpm package
opensuse/alsa&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/alsa&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-90781 | Med | 4.4 | < 1.2.16.1-2.1 | 1.2.16.1-2.1 | Sep 13, 2026 | alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved | |
| CVE-2009-0035 | Med | 5.5 | < 1.1.2-2.1 | 1.1.2-2.1 | Nov 9, 2019 | alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts. |
- affected < 1.2.16.1-2.1fixed 1.2.16.1-2.1
alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved
- affected < 1.1.2-2.1fixed 1.1.2-2.1
alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.