CVE-2026-32837

Publication date 17 March 2026

Last updated 25 March 2026


Ubuntu priority

Description

miniaudio version 0.11.25 and earlier contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers to trigger memory access violations by processing crafted WAV files. Attackers can exploit improper null-termination handling in the coding history field to cause out-of-bounds reads past the allocated metadata pool, resulting in application crashes or denial of service.

Status

Package Ubuntu Release Status
miniaudio 25.10 questing
Needs evaluation
24.04 LTS noble
Needs evaluation
22.04 LTS jammy Not in release


Access our resources on patching vulnerabilities