CVE-2022-48363

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/02/2023
Last modified:
13/05/2026

Description

In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:musicpd:music_player_daemon:*:*:*:*:*:*:*:* 0.23.8 (excluding)
cpe:2.3:o:linuxfoundation:automotive_grade_linux:-:*:*:*:*:*:*:*