THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-90781 (MEDIUM 4.4) — alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved

[NVD] CVE-2026-90781 (MEDIUM 4.4) — alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved

mednvdPublished 2026-09-13

CVE-2026-90781 CVSS: 4.4 MEDIUM Published: 2026-09-13T13:16:29.263

alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes one byte past a 64-byte buffer when parsing a name= field with 64 or more characters. Attackers can supply a long control-element identifier string through saved state files or command-line arguments to overwrite

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-90781