Alsa-project

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 5
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-56109

    ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c

    Last Modified: Jul 14, 2026
    Published: Jun 22, 2026

    CVE-2026-25068

    alsa-lib 1.2.15.2 Topology Decoder Heap-based Buffer Overflow

    Last Modified: Apr 16, 2026
    Published: Jan 29, 2026

    CVE-2019-13351

    posix/JackSocket.cpp in libjack in JACK2 1.9.1 through 1.9.12 (as distributed with alsa-plugins 1.1.7 and later) has a "double file descriptor close" issue during a failed connection attempt when jackd2 is not running. Exploitation success depends on multithreaded timing of that double close, which can result in unintended information disclosure, crashes, or file corruption due to having the wrong file associated with the file descriptor.

    Last Modified: Nov 21, 2024
    Published: Jul 05, 2019

    CVE-2009-0035

    alsa-utils: Insecure temporary file use in /usr/bin/alsa-info(.sh)

    Last Modified: Nov 21, 2024
    Published: Feb 09, 2009

    CVE-2005-0087

    security flaw

    Last Modified: Apr 16, 2026
    Published: Feb 15, 2005
    Items Per Page
    Alsa-Project Vulnerabilities & Security CVEs | CVE-DB