CVE-2026-31619

ALSA: fireworks: bound device-supplied status before string array lookup

References

Notes


      

Bugs

Status

Branch Status
upstream released (7.1-rc1) [07704bbf36f57e4379e4cadf96410dab14621e3b]
7.0-upstream-stable released (7.0.1) [682d8accf0d83a871e8c327b95c81f53902c922b]
6.19-upstream-stable released (6.19.14) [cc624b3d2be13297100539b64ad950695188e046]
6.18-upstream-stable released (6.18.24) [67cfd14074cdafab5de3f7cfc0952c1a9b653e5d]
6.12-upstream-stable released (6.12.83) [e103f98f6615ed2934e9cf340654f0cad9eb8a8a]
6.6-upstream-stable released (6.6.136) [f856f4b6efd51be7950e4b84c06cd961961ca41c]
6.1-upstream-stable released (6.1.175) [327f8e730e3c65ec97df9d3b07de66aeb3dc932d]
5.10-upstream-stable released (5.10.258) [183aa0de0f680496b9feb85c9d182681ad4600dd]
sid released (6.19.14-1)
6.12-trixie-security released (6.12.85-1)
6.1-bookworm-security needed
5.10-bullseye-security needed