CVE-2017-6892: Libsndfile Project Libsndfile

High severity, CVSS 8.8. EPSS: 2.5% chance of exploitation in the next 30 days.

In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.

Affected products

Published 2017-06-12. Last modified 2026-06-17.