The alsa-lib is a library to interface with ALSA in the Linux kernel and virtual devices using a plugin system. More detail: https://alsa.opensrc.org/Alsa-lib
Security Fix(es):
alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit 5f7fe33, contain a heap-based buffer overflow in the topology mixer control decoder. The tplgdecodecontrolmixer1() function reads the numchannels field from untrusted .tplg data and uses it as a loop bound without validating it against the fixed-size channel array (SNDTPLGMAXCHAN). A crafted topology file with an excessive numchannels value can cause out-of-bounds heap writes, leading to a crash.(CVE-2026-25068)
{
"severity": "Medium"
}{
"x86_64": [
"alsa-lib-1.2.3-2.oe2003sp4.x86_64.rpm",
"alsa-lib-debuginfo-1.2.3-2.oe2003sp4.x86_64.rpm",
"alsa-lib-debugsource-1.2.3-2.oe2003sp4.x86_64.rpm",
"alsa-lib-devel-1.2.3-2.oe2003sp4.x86_64.rpm"
],
"src": [
"alsa-lib-1.2.3-2.oe2003sp4.src.rpm"
],
"noarch": [
"alsa-topology-1.2.3-2.oe2003sp4.noarch.rpm",
"alsa-ucm-1.2.3-2.oe2003sp4.noarch.rpm"
],
"aarch64": [
"alsa-lib-1.2.3-2.oe2003sp4.aarch64.rpm",
"alsa-lib-debuginfo-1.2.3-2.oe2003sp4.aarch64.rpm",
"alsa-lib-debugsource-1.2.3-2.oe2003sp4.aarch64.rpm",
"alsa-lib-devel-1.2.3-2.oe2003sp4.aarch64.rpm"
]
}{
"x86_64": [
"alsa-lib-1.2.5.1-4.oe2203sp4.x86_64.rpm",
"alsa-lib-debuginfo-1.2.5.1-4.oe2203sp4.x86_64.rpm",
"alsa-lib-debugsource-1.2.5.1-4.oe2203sp4.x86_64.rpm",
"alsa-lib-devel-1.2.5.1-4.oe2203sp4.x86_64.rpm"
],
"src": [
"alsa-lib-1.2.5.1-4.oe2203sp4.src.rpm"
],
"noarch": [
"alsa-topology-1.2.5.1-4.oe2203sp4.noarch.rpm",
"alsa-ucm-1.2.5.1-4.oe2203sp4.noarch.rpm"
],
"aarch64": [
"alsa-lib-1.2.5.1-4.oe2203sp4.aarch64.rpm",
"alsa-lib-debuginfo-1.2.5.1-4.oe2203sp4.aarch64.rpm",
"alsa-lib-debugsource-1.2.5.1-4.oe2203sp4.aarch64.rpm",
"alsa-lib-devel-1.2.5.1-4.oe2203sp4.aarch64.rpm"
]
}{
"x86_64": [
"alsa-lib-1.2.10-4.oe2403.x86_64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403.x86_64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403.x86_64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403.x86_64.rpm",
"alsa-lib-1.2.10-4.oe2403sp1.x86_64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp1.x86_64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp1.x86_64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp1.x86_64.rpm",
"alsa-lib-1.2.10-4.oe2403sp2.x86_64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp2.x86_64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp2.x86_64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp2.x86_64.rpm",
"alsa-lib-1.2.10-4.oe2403sp3.x86_64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp3.x86_64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp3.x86_64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp3.x86_64.rpm"
],
"src": [
"alsa-lib-1.2.10-4.oe2403.src.rpm",
"alsa-lib-1.2.10-4.oe2403sp1.src.rpm",
"alsa-lib-1.2.10-4.oe2403sp2.src.rpm",
"alsa-lib-1.2.10-4.oe2403sp3.src.rpm"
],
"noarch": [
"alsa-topology-1.2.10-4.oe2403.noarch.rpm",
"alsa-ucm-1.2.10-4.oe2403.noarch.rpm",
"alsa-topology-1.2.10-4.oe2403sp1.noarch.rpm",
"alsa-ucm-1.2.10-4.oe2403sp1.noarch.rpm",
"alsa-topology-1.2.10-4.oe2403sp2.noarch.rpm",
"alsa-ucm-1.2.10-4.oe2403sp2.noarch.rpm",
"alsa-topology-1.2.10-4.oe2403sp3.noarch.rpm",
"alsa-ucm-1.2.10-4.oe2403sp3.noarch.rpm"
],
"aarch64": [
"alsa-lib-1.2.10-4.oe2403.aarch64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403.aarch64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403.aarch64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403.aarch64.rpm",
"alsa-lib-1.2.10-4.oe2403sp1.aarch64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp1.aarch64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp1.aarch64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp1.aarch64.rpm",
"alsa-lib-1.2.10-4.oe2403sp2.aarch64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp2.aarch64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp2.aarch64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp2.aarch64.rpm",
"alsa-lib-1.2.10-4.oe2403sp3.aarch64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp3.aarch64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp3.aarch64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp3.aarch64.rpm"
]
}{
"x86_64": [
"alsa-lib-1.2.10-4.oe2403sp1.x86_64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp1.x86_64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp1.x86_64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp1.x86_64.rpm"
],
"src": [
"alsa-lib-1.2.10-4.oe2403sp1.src.rpm"
],
"noarch": [
"alsa-topology-1.2.10-4.oe2403sp1.noarch.rpm",
"alsa-ucm-1.2.10-4.oe2403sp1.noarch.rpm"
],
"aarch64": [
"alsa-lib-1.2.10-4.oe2403sp1.aarch64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp1.aarch64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp1.aarch64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp1.aarch64.rpm"
]
}{
"x86_64": [
"alsa-lib-1.2.10-4.oe2403sp2.x86_64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp2.x86_64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp2.x86_64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp2.x86_64.rpm"
],
"src": [
"alsa-lib-1.2.10-4.oe2403sp2.src.rpm"
],
"noarch": [
"alsa-topology-1.2.10-4.oe2403sp2.noarch.rpm",
"alsa-ucm-1.2.10-4.oe2403sp2.noarch.rpm"
],
"aarch64": [
"alsa-lib-1.2.10-4.oe2403sp2.aarch64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp2.aarch64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp2.aarch64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp2.aarch64.rpm"
]
}{
"x86_64": [
"alsa-lib-1.2.10-4.oe2403sp3.x86_64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp3.x86_64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp3.x86_64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp3.x86_64.rpm"
],
"src": [
"alsa-lib-1.2.10-4.oe2403sp3.src.rpm"
],
"noarch": [
"alsa-topology-1.2.10-4.oe2403sp3.noarch.rpm",
"alsa-ucm-1.2.10-4.oe2403sp3.noarch.rpm"
],
"aarch64": [
"alsa-lib-1.2.10-4.oe2403sp3.aarch64.rpm",
"alsa-lib-debuginfo-1.2.10-4.oe2403sp3.aarch64.rpm",
"alsa-lib-debugsource-1.2.10-4.oe2403sp3.aarch64.rpm",
"alsa-lib-devel-1.2.10-4.oe2403sp3.aarch64.rpm"
]
}