PT-2026-22515 · Jarikomppa · Soloud
Oneafter
·
Published
2026-03-01
·
Updated
2026-03-13
·
CVE-2026-3393
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
jarikomppa soloud versions prior to 20200208
Description
A heap-based buffer overflow exists in the
SoLoud::Wav::loadflac function within the src/audiosource/wav/soloud wav.cpp file of the Audio File Handler component. This issue affects the processing of FLAC files. The exploit has been publicly disclosed and may be used for malicious purposes. The issue was reported to the project developers, but no response has been received. The attack requires local access.Recommendations
Versions prior to 20200208 should be updated. As a temporary workaround, consider restricting access to FLAC file handling or disabling the
SoLoud::Wav::loadflac function until a patch is available.Exploit
Fix
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Soloud