CVE-2025-52194

Name
CVE-2025-52194
Description
A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://bushido-sec.com/index.php/2025/08/08/libsndfile-buffer-overflow/
cve@mitre.org https://github.com/libsndfile
cve@mitre.org https://github.com/libsndfile/libsndfile/issues/1082

Match rules

CPE URI Source package Min version Max version
n/a == n/a == n/a
cpe:2.3:a:libsndfile_project:libsndfile:*:*:*:*:*:*:*:* libsndfile >= None <= 1.2.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libsndfile edge-main 1.2.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile edge-main 1.2.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile edge-main 1.2.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile edge-main 1.0.28-r8 None possibly vulnerable
libsndfile edge-main 1.0.28-r6 None possibly vulnerable
libsndfile edge-main 1.0.28-r4 None possibly vulnerable
libsndfile edge-main 1.0.28-r2 None possibly vulnerable
libsndfile edge-main 1.0.28-r1 None possibly vulnerable
libsndfile edge-main 1.0.28-r0 None possibly vulnerable
libsndfile 3.23-main 1.2.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.22-main 1.2.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.22-main 1.0.28-r8 None possibly vulnerable
libsndfile 3.22-main 1.0.28-r6 None possibly vulnerable
libsndfile 3.22-main 1.0.28-r4 None possibly vulnerable
libsndfile 3.22-main 1.0.28-r2 None possibly vulnerable
libsndfile 3.22-main 1.0.28-r1 None possibly vulnerable
libsndfile 3.22-main 1.0.28-r0 None possibly vulnerable
libsndfile 3.21-main 1.2.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.21-main 1.2.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.21-main 1.2.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.21-main 1.0.28-r8 None possibly vulnerable
libsndfile 3.21-main 1.0.28-r6 None possibly vulnerable
libsndfile 3.21-main 1.0.28-r4 None possibly vulnerable
libsndfile 3.21-main 1.0.28-r2 None possibly vulnerable
libsndfile 3.21-main 1.0.28-r1 None possibly vulnerable
libsndfile 3.21-main 1.0.28-r0 None possibly vulnerable
libsndfile 3.20-main 1.2.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.20-main 1.2.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.20-main 1.0.28-r8 None possibly vulnerable
libsndfile 3.20-main 1.0.28-r6 None possibly vulnerable
libsndfile 3.20-main 1.0.28-r4 None possibly vulnerable
libsndfile 3.20-main 1.0.28-r2 None possibly vulnerable
libsndfile 3.20-main 1.0.28-r1 None possibly vulnerable
libsndfile 3.20-main 1.0.28-r0 None possibly vulnerable
libsndfile 3.19-main 1.2.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.19-main 1.2.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
libsndfile 3.19-main 1.0.28-r8 None possibly vulnerable
libsndfile 3.19-main 1.0.28-r6 None possibly vulnerable
libsndfile 3.19-main 1.0.28-r4 None possibly vulnerable
libsndfile 3.19-main 1.0.28-r2 None possibly vulnerable
libsndfile 3.19-main 1.0.28-r1 None possibly vulnerable
libsndfile 3.19-main 1.0.28-r0 None possibly vulnerable