Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-56226

Опубликовано: 14 янв. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.

A flaw was found in the libsndfile library. This issue occurs when encoding MP3 files. During initialization, when an unsupported sample rate is detected, encoding resources are not released within the error-handling path due to an incomplete initialization, impacting system performance and resulting in a denial of service.

Отчет

To exploit this flaw, an attacker needs to be able to process a malicious MP3 file with an application linked to the libsndfile library. Also, the only security impact of this issue is a high consumption of system memory that eventually can cause an application crash and result in a denial of service, there is no memory corruption or arbitrary code execution. Due to these reasons, this vulnerability has been rated with a moderate severity.

Меры по смягчению последствий

Do not process untrusted MP3 files with the libsndfile library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10libsndfileFix deferred
Red Hat Enterprise Linux 6libsndfileOut of support scope
Red Hat Enterprise Linux 7libsndfileNot affected
Red Hat Enterprise Linux 8libsndfileNot affected
Red Hat Enterprise Linux 9libsndfileNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-401
https://bugzilla.redhat.com/show_bug.cgi?id=2429564libsndfile: memory leak when encoding MP3 files due to an incomplete initialization

EPSS

Процентиль: 25%
0.00087
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
3 месяца назад

Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.

CVSS3: 5.3
nvd
3 месяца назад

Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.

CVSS3: 5.3
msrc
2 месяца назад

Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.

CVSS3: 5.3
debian
3 месяца назад

Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3 ...

CVSS3: 5.3
redos
около 1 месяца назад

Уязвимость libsndfile

EPSS

Процентиль: 25%
0.00087
Низкий

5.3 Medium

CVSS3