AZL-106800

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106800.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106800
Upstream
Published
2026-09-24T21:18:57Z
Modified
2026-10-10T05:36:40Z
Summary
CVE-2026-88386 affecting package libsndfile 1.2.2-5
Details

libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination address to unsigned int * and perform a 4-byte store. This results in undefined behavior leading to denial of service.

References

Affected packages

Azure Linux:3 / libsndfile

Package

Name
libsndfile
Purl
pkg:rpm/azure-linux/libsndfile

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.2.2-5

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106800.json"