CVE-2014-9496: Canonical Ubuntu Linux
Low severity, CVSS 2.1. EPSS: 0.6% chance of exploitation in the next 30 days.
The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only; version 15.10 only
- Debian Debian Linux: version 9.0 only
- Libsndfile Project Libsndfile: before 1.0.26 (fixed in 1.0.26)
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Oracle Solaris: version 11.2 only
Published 2015-01-16. Last modified 2026-06-17.