---
id: CVE-2026-88386
title: >-
  libsndfile 1.2.2 contains a misaligned memory access issue in
  psf_binheader_readf() while parsing WAV fmt chunks
summary: >-
  libsndfile 1.2.2 contains a misaligned memory access issue in
  psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV
  file can cause the function to cast an unaligned destination address to
  unsigned int * and perform …
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-122
  - CWE-843
vendor: Red Hat
product: Red Hat Enterprise Linux 10
affected:
  - enterprise_linux 10
  - enterprise_linux 6
  - enterprise_linux 7
  - enterprise_linux 8
  - enterprise_linux 9
  - enterprise_linux_ai_rhel_ai 3
published: '2026-09-24'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T17:17:17.833'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88386'
references:
  - url: 'https://github.com/libsndfile/libsndfile/issues/1150'
    label: cve@mitre.org
  - url: >-
      https://github.com/mhlavink/libsndfileci/commit/474e4d328b1e6240b93ec6ed14efb7c6a44bee57
    label: cve@mitre.org
  - url: 'https://github.com/libsndfile/libsndfile/issues/1150'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88386.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-88386'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2540836'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-88386'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-88386'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-25T16:48:59.681171Z'
ingestedAt: '2026-09-24T20:51:40.266Z'
epss: 0.00145
epssPercentile: 0.0311
---

## Overview

libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination address to unsigned int * and perform a 4-byte store. This results in undefined behavior leading to denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Enterprise Linux AI (RHEL AI) 3 · no fix planned: Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-88386.json)
