🛡️ ECHO-47f1-73fb-7e9f — pulseaudio
Description
Multiple unbounded alloca() calls in the PulseAudio protocol server, which
an attacker can drive into a stack overflow by sending oversized protocol
messages.
The vulnerable code is the server side of the protocol. It builds into the
PulseAudio daemon, shipped in the pulseaudio binary package, described by
Debian as the "PulseAudio sound server". Echo containers do not install
that package. What they pull in, as a transitive dependency of Chromium's
audio support, is libpulse0 — the "PulseAudio client libraries" — which
ships only libpulse, libpulse-simple and libpulsecommon. There is no
protocol server in those objects and no daemon on the image to reach.
libpulse0 is flagged only because it is built from the same pulseaudio
source package that the advisory names, so a source-level match tags every
binary package built from it, including ones that carry none of the
affected code.
Upstream attributes the flaw to PipeWire rather than PulseAudio. Red Hat
files it as "pipewire: Pulse Server alloca Stack Overflow", NVD lists
pipewire and libkrun as the affected packages, and Ubuntu's fix patches
only PipeWire sources — module-protocol-pulse/pulse-server.c, message.c
and defs.h. Debian tracks CVE-2026-14324, the sibling issue from that same
advisory, against the pipewire source package, but filed this one under
pulseaudio. No Echo image installs pipewire in any form.
Verified on the built image: libpulse0 is the only pulse-related package
present, with no daemon binary, no pipewire and no wireplumber. Its three
objects — libpulse, libpulse-simple and libpulsecommon — export no
protocol-server symbols and reference none of the affected sources; the
source files they were built from are client and common code only, with no
protocol-native.c.
Debian rates the issue minor and marks it <no-dsa> for trixie. It is
unfixed in every suite — trixie has 17.0+dfsg1-2 and forky/sid have
17.0+dfsg1-2.1, both vulnerable — so there is no version to move to even
if it did apply.
This statement is about which binary package carries the code, so it holds
for as long as the image installs the client libraries without the daemon.
MUST be re-evaluated if the pulseaudio package is ever added.
https://security-tracker.debian.org/tracker/CVE-2026-14330
Affected software
ECHO-47f1-73fb-7e9f is recorded against 1 package.
- pulseaudio (fixed in 17.0+dfsg1-2)
Timeline and source
Published on 2 July 2026 and last revised on 30 July 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| pulseaudio | — | 17.0+dfsg1-2 |
References
Similar Threats
- Unknown DEBIAN-CVE-2026-14330
- Unknown MINI-cfrw-2485-q2m3
- Unknown CGA-35cq-2vhq-cmvf
- Unknown AZL-53525
- Unknown AZL-53627
More ECHO 4 advisories
Browse all of ECHO 4 in the advisory index.
- ECHO-46fc-3288-0ab3
- ECHO-47a7-0e33-abab
- ECHO-47b6-8d6b-c714
- ECHO-47de-5d2a-48d4
- ECHO-47e1-8fa8-b833
- ECHO-47e4-5b68-7dd8
- ECHO-47e5-ceaa-7523
- ECHO-47eb-2c54-a673
- ECHO-47f3-9088-8b24
- ECHO-48a3-dcb9-730d
- ECHO-48ad-a087-776b
- ECHO-48af-523d-62b5
- ECHO-48b5-0c84-55da
- ECHO-48bb-6383-ba42
- ECHO-48c0-4c3c-3a0d
- ECHO-48dd-029f-8278
Free Vulnerability Check
Is your site affected by ECHO-47f1-73fb-7e9f?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against ECHO-47f1-73fb-7e9f and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.