In libsndfile version 1.0.28, an error in the "aiffreadchanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-6892.json"