CVE-2021-4156
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
23/03/2022
Last modified:
11/12/2025
Description
An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:libsndfile_project:libsndfile:1.1.10:*:*:*:*:*:*:* | ||
| cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://bugzilla.redhat.com/show_bug.cgi?id=2027690
- https://github.com/libsndfile/libsndfile/issues/731
- https://github.com/libsndfile/libsndfile/pull/732/commits/4c30646abf7834e406f7e2429c70bc254e18beab
- https://lists.debian.org/debian-lts-announce/2022/06/msg00020.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00036.html
- https://security.gentoo.org/glsa/202309-11
- https://bugzilla.redhat.com/show_bug.cgi?id=2027690
- https://github.com/libsndfile/libsndfile/issues/731
- https://github.com/libsndfile/libsndfile/pull/732/commits/4c30646abf7834e406f7e2429c70bc254e18beab
- https://lists.debian.org/debian-lts-announce/2022/06/msg00020.html
- https://lists.debian.org/debian-lts-announce/2022/09/msg00036.html
- https://lists.debian.org/debian-lts-announce/2025/12/msg00013.html
- https://security.gentoo.org/glsa/202309-11



