Updated libalsa2 packages fix security vulnerabilities
Publication date: 02 Sep 2026Modification date: 02 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-25068 , CVE-2026-56109
Description
alsa-lib 1.2.15.2 Topology Decoder Heap-based Buffer Overflow.
(CVE-2026-25068)
ALSA Library < 1.2.16.1 Double-Free via parse_def() in conf.c.
(CVE-2026-56109)
References
- https://bugs.mageia.org/show_bug.cgi?id=35934
- https://ubuntu.com/security/notices/USN-8044-1
- https://ubuntu.com/security/notices/USN-8538-1
- https://lore.kernel.org/alsa-devel/CAGt8pqBU0p2voB+qHxWGcNJrKHAcBhAyHUUBPLBN-Yj_SiV6MQ@mail.gmail.com/
- https://www.cve.org/CVERecord?id=CVE-2026-25068
- https://www.cve.org/CVERecord?id=CVE-2026-56109
SRPMS
10/core
- libalsa2-1.2.15.2-1.1.mga10
9/core
- libalsa2-1.2.9-1.1.mga9