CVE-2025-52194

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.
Configurations

Configuration 1 (hide)

cpe:2.3:a:libsndfile_project:libsndfile:*:*:*:*:*:*:*:*

History

11 Sep 2025, 18:17

Type Values Removed Values Added
First Time Libsndfile Project libsndfile
Libsndfile Project
References () https://bushido-sec.com/index.php/2025/08/08/libsndfile-buffer-overflow/ - () https://bushido-sec.com/index.php/2025/08/08/libsndfile-buffer-overflow/ - Broken Link
References () https://github.com/libsndfile - () https://github.com/libsndfile - Product
References () https://github.com/libsndfile/libsndfile/issues/1082 - () https://github.com/libsndfile/libsndfile/issues/1082 - Exploit, Issue Tracking, Patch, Vendor Advisory
CPE cpe:2.3:a:libsndfile_project:libsndfile:*:*:*:*:*:*:*:*

22 Aug 2025, 18:09

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de desbordamiento de búfer en libsndfile versión 1.2.2 y posiblemente versiones anteriores al procesar archivos de audio IRCAM malformados. La vulnerabilidad se produce en la función ircam_read_header en src/ircam.c:164 durante el procesamiento de la frecuencia de muestreo, lo que provoca corrupción de memoria y posible ejecución de código.

21 Aug 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-121

21 Aug 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-21 15:15

Updated : 2025-09-11 18:17


NVD link : CVE-2025-52194

Mitre link : CVE-2025-52194

CVE.ORG link : CVE-2025-52194


JSON object : View

Products Affected

libsndfile_project

  • libsndfile
CWE
CWE-121

Stack-based Buffer Overflow