Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90204.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-90204
Upstream
Published
2026-06-22T18:16:48Z
Modified
2026-09-01T05:28:09Z
Summary
CVE-2026-56109 affecting package alsa-lib for versions less than 1.2.16.1-1
Details

The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parsedef() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parsedef() fails to check return values before continuing, causing sndconfigdelete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.

References

Affected packages

Azure Linux:3 / alsa-lib

Package

Name
alsa-lib
Purl
pkg:rpm/azure-linux/alsa-lib

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.16.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90204.json"