CVE-2026-14330 Details
Description
Multiple unbounded alloca() calls in the PulseAudio protocol server.
A vulnerability exists in the PipeWire PulseAudio protocol server due to multiple unbounded alloca() calls. These calls allocate memory based on parameters from audio cards or client properties without proper validation. This flaw can be exploited by a malicious PulseAudio client to send requests with excessively large parameter counts, leading to stack exhaustion and causing the PipeWire daemon to crash.
No practical mitigation is available other than upgrading, as the PulseAudio protocol server is essential for compatibility with PulseAudio applications.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 26, 2026 | CVE Modified | [email protected] |
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |