Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.
References
| Link | Resource |
|---|---|
| https://gist.github.com/Sisyphus-wang/f9e6e017b7d478bebee6e8187672abc8 | Exploit Third Party Advisory |
| https://github.com/libsndfile/libsndfile/issues/1089 | Exploit Issue Tracking |
Configurations
History
21 Jan 2026, 21:21
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:libsndfile_project:libsndfile:*:*:*:*:*:*:*:* | |
| First Time |
Libsndfile Project
Libsndfile Project libsndfile |
|
| References | () https://gist.github.com/Sisyphus-wang/f9e6e017b7d478bebee6e8187672abc8 - Exploit, Third Party Advisory | |
| References | () https://github.com/libsndfile/libsndfile/issues/1089 - Exploit, Issue Tracking |
14 Jan 2026, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-14 15:15
Updated : 2026-01-21 21:21
NVD link : CVE-2025-56226
Mitre link : CVE-2025-56226
CVE.ORG link : CVE-2025-56226
JSON object : View
Products Affected
libsndfile_project
- libsndfile
CWE
CWE-401
Missing Release of Memory after Effective Lifetime
