---
id: CVE-2026-88372
title: >-
  libsndfile 1.2.2 contains an integer overflow vulnerability in
  mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.
summary: >-
  libsndfile 1.2.2 contains an integer overflow vulnerability in
  mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-190
published: '2026-09-24'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T21:04:40.340'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88372'
references:
  - url: 'https://github.com/libsndfile/libsndfile/issues/1151'
    label: cve@mitre.org
  - url: 'https://github.com/libsndfile/libsndfile/issues/1151'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88372.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-88372'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2540421'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-88372'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88372'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
  - score-dispute
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-24T17:57:29.323451Z'
ingestedAt: '2026-09-24T16:47:15.898Z'
vendor: Red Hat
product: Red Hat Enterprise Linux 10
affected:
  - enterprise_linux 10
  - enterprise_linux 6
  - enterprise_linux 7
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
scores:
  nvd: 7.5
  vendor: 5.5
---

## Overview

libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88372.json)
