Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcmunpack24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing a malicious HTTP audio source to cause the unpack loop to write 1366 entries into a 1365-entry buffer, overwriting four bytes past the array boundary with three attacker-controlled bytes from an HTTP response body, resulting in daemon termination or potential code execution.
{
"cwe_ids": [
"CWE-193"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49127.json",
"cna_assigner": "VulnCheck"
}"2026-08-12T16:25:34Z"
[
{
"id": "CVE-2026-49127-04752775",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"71964305151459929063365073686973412717",
"94297991698096131898126521523883973900",
"4345581707635043188001349382395809212",
"85598913466137857182632450421836979641",
"317853513465551354023647088632355388735",
"55623726006400287909893796865533190058",
"114968530484658525328972131398426724298",
"105669709270122329687866350919396195869"
]
},
"source": "https://github.com/musicplayerdaemon/mpd/commit/59911028c020f84bc2e669da6a1ef88121301274",
"target": {
"file": "src/decoder/plugins/PcmDecoderPlugin.cxx"
}
},
{
"id": "CVE-2026-49127-7a608c70",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 3456.0,
"function_hash": "56620212230690523836152124316530138200"
},
"source": "https://github.com/musicplayerdaemon/mpd/commit/59911028c020f84bc2e669da6a1ef88121301274",
"target": {
"function": "pcm_stream_decode",
"file": "src/decoder/plugins/PcmDecoderPlugin.cxx"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49127.json"