🛡️ MGASA-2026-0215 — libsndfile
Description
Updated libsndfile packages fix security vulnerabilities
CVE-2025-52194 A buffer overflow vulnerability exists in libsndfile
version 1.2.2 and potentially earlier versions when processing malformed
IRCAM audio files. The vulnerability occurs in the ircam_read_header
function at src/ircam.c:164 during sample rate processing, leading to
memory corruption and potential code execution.
CVE-2025-56226 Libsndfile <=1.2.2 contains a memory leak vulnerability
in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.
CVE-2026-37555 An issue was discovered in libsndfile 1.2.2 IMA ADPCM
codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast,
but the WAV code path (line 235) and close path (line 167) were not.
When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit
multiplication overflows before being assigned to sf.frames
(sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the
product 2500000000 overflows to -1794967296. This causes incorrect frame
count leading to heap buffer overflow or denial of service. Both values
come from the WAV file header and are attacker-controlled. This issue
was discovered after an incomplete fix for CVE-2022-33065.
Affected software
MGASA-2026-0215 is recorded against 1 package.
- libsndfile (fixed in 1.2.0-3.3.mga9)
Timeline and source
Published on 16 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| libsndfile | — | 1.2.0-3.3.mga9 |
References
Similar Threats
- Unknown ALSA-2026:19559
- Unknown ALSA-2026:19560
- Unknown ALSA-2026:19610
- Unknown AZL-66669
- Unknown AZL-66671
More MGASA 2026 advisories
Browse all of MGASA 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by MGASA-2026-0215?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2026-0215 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.