ThreatCluster

Buffer Overflow Vulnerabilities in ALSA Impacting Audio Drivers

First seen 18 Feb 2026, 09:15 UTC Api.Msrc.Microsoft 48

Article Content

Browse articles
ThreatCluster

Two buffer overflow vulnerabilities have been identified in ALSA audio drivers, affecting the UMP SysEx message conversion and the tuning control for the CA0132 codec. The vulnerabilities are tracked as CVE-2025-37891 and CVE-2025-39751, with the former published on May 19, 2025, and the latter on September 11, 2025.

Timeline

2025-05-19
CVE-2025-37891 published
2025-09-11
CVE-2025-39751 published
2026-02-18
Information published regarding both vulnerabilities