CVE-2018-7263: Underbit Libmad

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.

Affected products

  • Underbit Libmad: up to and including 0.15.1b

Published 2018-02-20. Last modified 2026-06-17.