Libsndfile is a widely embedded audio-file parsing library that, despite maintaining a narrow product scope, occupies a prominent position across multimedia applications, audio processing tools, and media frameworks due to its deep integration into software supply chains. The vendor's vulnerability disclosures cluster around memory-safety and arithmetic weaknesses—out-of-bounds reads and writes, improper buffer-boundary enforcement, divide-by-zero conditions, and integer overflow—that are characteristic of C-based parsers handling untrusted audio file formats. These weakness classes reflect the inherent complexity of safely decoding diverse audio codecs and container formats, and a single flaw can propagate to every downstream application that links the library, amplifying the significance of each disclosure relative to volume. Defenders should prioritize tracking this vendor's updates and inventory applications that embed the library, since remediation typically depends on downstream vendors rebuilding and releasing patched versions; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libsndfile Project over time
Signals from CVEs in this vendor scope (32 CVEs).
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-37555HIGH An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 1 | Apr 29, 2026 | 8.2 | 35 | NO | NO |
CVE-2017-12562CRITICAL Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or | Aug 5, 2017 | 9.8 | 33 | NO | NO |
CVE-2017-8361HIGH The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecifi | Apr 30, 2017 | 8.8 | 30 | NO | NO |
CVE-2021-3246HIGH A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file. | Jul 20, 2021 | 8.8 | 29 | NO | NO |
CVE-2017-6892HIGH In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF fil | Jun 12, 2017 | 8.8 | 29 | NO | NO |
CVE-2018-13139HIGH A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified o | Jul 4, 2018 | 8.8 | 27 | NO | NO |
CVE-2017-14246HIGH An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and | Sep 21, 2017 | 8.1 | 27 | NO | NO |
CVE-2017-14245HIGH An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and | Sep 21, 2017 | 8.1 | 27 | NO | NO |
CVE-2018-19662HIGH An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service. | Nov 29, 2018 | 8.1 | 26 | NO | NO |
CVE-2025-52194HIGH A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the irc | Aug 21, 2025 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (32 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libsndfile Project.
Media articles that mention a CVE ID that affects a product developed by Libsndfile Project — matched by CVE ID, not by vendor name.