Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing a malicious HTTP audio source to cause the unpack loop to write 1366 entries into a 1365-entry buffer, overwriting four bytes past the array boundary with three attacker-controlled bytes from an HTTP response body, resulting in daemon termination or potential code execution.
References
Configurations
No configuration.
History
28 May 2026, 22:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
28 May 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-28 20:16
Updated : 2026-05-29 14:07
NVD link : CVE-2026-49127
Mitre link : CVE-2026-49127
CVE.ORG link : CVE-2026-49127
JSON object : View
Products Affected
No product.
CWE
CWE-193
Off-by-one Error
