Description
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3058-1 | libsndfile security update |
Debian DLA |
DLA-3126-1 | libsndfile security update |
Debian DLA |
DLA-4402-1 | libsndfile security update |
EUVD |
EUVD-2021-34024 | An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws. |
Ubuntu USN |
USN-5409-1 | libsndfile vulnerability |
Ubuntu USN |
USN-7273-1 | libsndfile vulnerabilities |
References
History
Thu, 11 Dec 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-12-11T12:06:14.134Z
Reserved: 2021-12-22T00:00:00.000Z
Link: CVE-2021-4156
No data.
Status : Modified
Published: 2022-03-23T20:15:10.097
Modified: 2025-12-11T13:15:57.710
Link: CVE-2021-4156
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN