{"id":"CVE-2026-88386","details":"libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination address to unsigned int * and perform a 4-byte store. This results in undefined behavior leading to denial of service.","modified":"2026-09-26T08:04:51.531327Z","published":"2026-09-24T00:00:00Z","database_specific":{"cna_assigner":"mitre","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88386.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88386.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88386"},{"type":"REPORT","url":"https://github.com/libsndfile/libsndfile/issues/1150"},{"type":"FIX","url":"https://github.com/mhlavink/libsndfileci/commit/474e4d328b1e6240b93ec6ed14efb7c6a44bee57"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mhlavink/libsndfileci","events":[{"introduced":"0"},{"fixed":"474e4d328b1e6240b93ec6ed14efb7c6a44bee57"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["190642809612830024040507097100744851011","11635448475859027199261771146491725754","131381947107464823377491167462973846680","284707267631807798073438361206436919319","34505237038824726757080437940202375241","320081295030776192403044112273077767299","332255076382866677878367151196166209433","182779027972104884113978482629914540686","51820261861957590423894039301556095241","33200899429852184798819865838649595293","331374858751118920765061593206466961490","65541195434954043230603713777939061706","231890915529087916424417395860293628322","308629704071130943103856648868184810446","263277073001971615280005349507939448543","11727145900727432498269583248593936661","196762744839051992429430520725389189334","121507669718064606891221817282333396299","171212851073556904916543851978326718594","48972189834757130087662782673145418554","194792816923135376215200174238584632083","252498429386771619760339843534227082483","194716589095770382964766774445009374955","37127342892222934708025498463173154968","112671232697266024072197431021445962324","284602852667642016158512276675079404568","256024446486490626826757447490266905860","236249225431122543636810380873525237160","70174920340812276153894683311138123556","201663304761844187724961589186205223465","84314204412769948148088917365066033911","242229915656002755371463768756794094749","5606167875321317593317509557646455133","216839743244953127728450067675065294112","157639189127705122549551512562188248454","23800559776335499999668453492194151667","282505239558139795985383126761140303669","253246167932122943864955190295209387515","278312016632028743399648170114828477442","114931106382270817327930000416921786256","229335052279171403659193692620482282419","93091389551383703399866840121761960688","116583913252374387690842965024159206687","146242049092265078716648133928208099483","79449070442492205077870188081587620321","269595265748110472451993564431953919559","88700164511071719793321767045086678102","166904072919649215469705086269968615000","331374858751118920765061593206466961490","176655231198527463523407495290032903610","320312701579705489823425015887437270672","99363321451721958068934959468105282722","310127536070887678247180683676433856432","174275643817724588901598340989806796995","261827768092294820898535381015581205563","183320008138077277739562046023452643825","310951784744637904449206301658421008028","289412875790646218130469332966605259774","271306002149946611864276667751984866992","329051244206836312936591255277171115818","176074128964214444768464254343690865341","267422569832780145486960012810860863702","295901336179860599912097530898642912844","206275597060174975225374241889652898151","289572893099714487925306398916392767826","76109569358558780506506012991308418490","94014256077658031815581422551731436770","184826220535957206720286660120493585452","134173896619952622894571247936721678709","162598015513172343976388615882110253123","99934725439039894701442854153507748140","14866447698012634116792553910547932036","232263568713402618681177763798248334295","57372676576784896182789464569370781402","31375743030241817176560897589706194596","107188496238524129321089291649018849074","215645679092976721657847947119989451730","203986711380297107375000522872461902552","319432666229415879990415528395695495762","218915771855870276690461720442323795322","99610273976506733263157948146117733593","290910461279907583677566758559108399454","178286796177985683418821329757164088546","308843424304670851912893359458486032938"],"threshold":0.9},"id":"CVE-2026-88386-8b56af95","signature_type":"Line","signature_version":"v1","source":"https://github.com/mhlavink/libsndfileci/commit/474e4d328b1e6240b93ec6ed14efb7c6a44bee57","target":{"file":"src/common.c"}},{"digest":{"function_hash":"173081823208909466343538746340080441140","length":3902},"id":"CVE-2026-88386-a06303b6","signature_type":"Function","signature_version":"v1","source":"https://github.com/mhlavink/libsndfileci/commit/474e4d328b1e6240b93ec6ed14efb7c6a44bee57","target":{"file":"src/common.c","function":"psf_binheader_readf"},"deprecated":false}],"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-88386.json","vanir_signatures_modified":"2026-09-26T08:04:51Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}