PatchSiren

libsndfile CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM libsndfile CVE published 2026-09-24

CVE-2026-88386

CVE-2026-88386 is a denial-of-service vulnerability in libsndfile 1.2.2. A specially crafted WAV file can cause undefined behavior in the psf_binheader_readf() function, leading to a denial of service. This CVE was published on 2026-09-24T21:18:57.003Z and was last modified on 2026-09-25T17:17:17.833Z. The vulnerability arises from a misaligned memory access issue when parsing WAV fmt chunks. Defenders sh [truncated]