Your message dated Sat, 11 Jul 2026 16:17:06 +0000
with message-id <[email protected]>
and subject line Bug#1126629: fixed in alsa-lib 1.2.14-1+deb13u1
has caused the Debian Bug report #1126629,
regarding alsa-lib: CVE-2026-25068
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1126629: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1126629
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: alsa-lib
Version: 1.2.15.3-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for alsa-lib.
CVE-2026-25068[0]:
| alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to
| commit 5f7fe33, contain a heap-based buffer overflow in the topology
| mixer control decoder. The tplg_decode_control_mixer1() function
| reads the num_channels field from untrusted .tplg data and uses it
| as a loop bound without validating it against the fixed-size channel
| array (SND_TPLG_MAX_CHAN). A crafted topology file with an excessive
| num_channels value can cause out-of-bounds heap writes, leading to a
| crash.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-25068
https://www.cve.org/CVERecord?id=CVE-2026-25068
[1]
https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: alsa-lib
Source-Version: 1.2.14-1+deb13u1
Done: Moritz Mühlenhoff <[email protected]>
We believe that the bug you reported is fixed in the latest version of
alsa-lib, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Moritz Mühlenhoff <[email protected]> (supplier of updated alsa-lib package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 19 Jun 2026 20:17:25 +0200
Source: alsa-lib
Architecture: source
Version: 1.2.14-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian ALSA Maintainers <[email protected]>
Changed-By: Moritz Mühlenhoff <[email protected]>
Closes: 1126629
Changes:
alsa-lib (1.2.14-1+deb13u1) trixie; urgency=medium
.
* CVE-2026-25068 (Closes: #1126629)
Checksums-Sha1:
e9b72a36312ff975223cc38ef5f2a5aadbff742e 2951 alsa-lib_1.2.14-1+deb13u1.dsc
18ce56b9ec4f53c230036112821c757c459f7a22 34100
alsa-lib_1.2.14-1+deb13u1.debian.tar.xz
08ba8c6e72f9964ab3f510ff1cd5d127f7cdea48 12034
alsa-lib_1.2.14-1+deb13u1_amd64.buildinfo
Checksums-Sha256:
45f15d45b0329394de2e59c85052d0ac084e4e0ac215346ac5299a09432f515e 2951
alsa-lib_1.2.14-1+deb13u1.dsc
8c04f2d76c4566f21d044ea52eed39d97bdbf5a5a9cb21582662dd76f2dad38e 34100
alsa-lib_1.2.14-1+deb13u1.debian.tar.xz
1e2b4653c0e0344bc2ed03f053b472d2f349c3e31c18cec409f1322c374524a3 12034
alsa-lib_1.2.14-1+deb13u1_amd64.buildinfo
Files:
ef92cc7330ee3200f078969cae7f18b4 2951 libs optional
alsa-lib_1.2.14-1+deb13u1.dsc
77a4c2a2a95e73bb6181e5ad2c9f459b 34100 libs optional
alsa-lib_1.2.14-1+deb13u1.debian.tar.xz
b914d5eeb0425aa67f0f664a8ff949a4 12034 libs optional
alsa-lib_1.2.14-1+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmo6rVwACgkQEMKTtsN8
TjYTWRAAkT95OuQ1RMKnNxY4Fg0ocji9DglRLe9xrykiLuc15RYF1q7wwLfFRBXm
4MNfzScoaHEllthDyzwMhikQdB/fc8ucwcD4p57Un+b/aZbAwI4n0PwhmCcE9q5x
Y0HzzxLLC1/1BXM+aEJtJ2CwbOX8G64E/stwooEdiPetaGPqDb+ISwdeGxcXB4nF
aR3IgOcRsQHuOeEUbs7HKhxIOeaa6s97DHSrfpYkqkJTHVZ+emATYeXuo/pghSQe
MDvc4glESLFp64w22jZFCM61UOu0+h+BvnPHM4qfEl22BPDuWfqHPJfieTvdruGK
vgMoXrWljBremPn2M1Lt8+5csEbucrE0u7QJIvgadvKtW7VYC4Diuo87ZYXQV6EV
Y0RnrITJ7LXYshCx7h2OYCErJ/aKMhC41QXDmnQVMi/14uiSlsTLzU5xRRkYnNaN
LpIX96ZzfMx2mLlIY9U9NaNt4U4bG4RPlVGyy1k7Xf/hzVRmfU+CybFGhTxuFDy9
70A5qQWkt3ivpGRf2arSailvuBqEboiAUQLcnz/NSR19HqADOWEtr87AjR+cWy9B
uyRI+1XXyioiTKXffQ5H1Y8RJ1Yz8HEQu6i0myB42aU/jsjBQK+TuQjfKcBMIk0P
WihbQb7Sw12R7BtSALotx/3A0o+zM3934EcbY/XFFDCEiuyBrk4=
=oGok
-----END PGP SIGNATURE-----
pgpGNdr08b6kZ.pgp
Description: PGP signature
--- End Message ---