CVE-2025-52194

EUVD-2025-25491
A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ircam_read_header function at src/ircam.c:164 during sample rate processing, leading to memory corruption and potential code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Affected Products (NVD)
VendorProductVersion
libsndfile_projectlibsndfile
𝑥
≤ 1.2.2
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libsndfile-devel
suse enterprise desktop 15 SP7
1.0.28-150000.5.23.1
fixed
suse enterprise sap 15 SP4
1.0.28-150000.5.23.1
fixed
suse enterprise sap 15 SP5
1.0.28-150000.5.23.1
fixed
suse enterprise sap 15 SP6
1.0.28-150000.5.23.1
fixed
suse enterprise sap 15 SP7
1.0.28-150000.5.23.1
fixed
suse enterprise server 12 SP5
1.0.25-36.32.1
fixed
suse enterprise server 15 SP4
1.0.28-150000.5.23.1
fixed
suse enterprise server 15 SP5
1.0.28-150000.5.23.1
fixed
suse enterprise server 15 SP6
1.0.28-150000.5.23.1
fixed
suse enterprise server 15 SP7
1.0.28-150000.5.23.1
fixed
libsndfile1
suse enterprise desktop 15 SP7
1.0.28-150000.5.23.1
fixed
suse enterprise sap 15 SP4
1.0.28-150000.5.23.1
fixed
suse enterprise sap 15 SP5
1.0.28-150000.5.23.1
fixed
suse enterprise sap 15 SP6
1.0.28-150000.5.23.1
fixed
suse enterprise sap 15 SP7
1.0.28-150000.5.23.1
fixed
suse enterprise server 12 SP3
1.0.25-36.32.1
fixed
suse enterprise server 12 SP5
1.0.25-36.32.1
fixed
suse enterprise server 15 SP4
1.0.28-150000.5.23.1
fixed
suse enterprise server 15 SP5
1.0.28-150000.5.23.1
fixed
suse enterprise server 15 SP6
1.0.28-150000.5.23.1
fixed
suse enterprise server 15 SP7
1.0.28-150000.5.23.1
fixed
libsndfile1-32bit
suse enterprise server 12 SP3
1.0.25-36.32.1
fixed
suse enterprise server 12 SP5
1.0.25-36.32.1
fixed