[Security] Segmentation Fault DoS in snd_config_load_string via corrupted linked list pointer

GitHub issues - opened <[email protected]> Sat, 4 Jul 2026 14:07:38 +0200 (CEST)
Newsgroups org.alsa-project.alsa-devel
Message-ID <[email protected]>
alsa-project/alsa-lib issue #514 was opened from eglonnnn:

### Description

A segmentation fault vulnerability in alsa-lib v1.2.15.3. When `snd_config_load_string()` parses a crafted ALSA configuration text, the parser produces an inconsistent linked-list state during array/composite node handling, causing `list_del()` to access an uninitialized pointer and trigger a SEGV.

### Impact

- Denial-of-service via process crash
- Any application processing untrusted ALSA configuration text is affected

### Reproduction

All materials are available in my research repository:

https://github.com/eglonnnn/opensource-fuzz-vulnerability-research/tree/main/SEGV%20in%20alsa-lib%20snd_config_load_string

Issue URL     : https://github.com/alsa-project/alsa-lib/issues/514
Repository URL: https://github.com/alsa-project/alsa-lib