CVE-2014-9496: Canonical Ubuntu Linux

Low severity, CVSS 2.1. EPSS: 0.6% chance of exploitation in the next 30 days.

The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
  • Debian Debian Linux: version 9.0 only
  • Libsndfile Project Libsndfile: before 1.0.26 (fixed in 1.0.26)
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Oracle Solaris: version 11.2 only

Published 2015-01-16. Last modified 2026-06-17.