CVE-2025-56226: Medium severity libsndfile vulnerability
Published Jan 14, 2026
·Updated
Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpegl3encoderinit() function within the mpegl3encode.c file.
Affected Software
2 affected components
libsndfile<=1.2.2
Libsndfile Project Libsndfile>=1.1.0<=1.2.2
Event History
Jan 14, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-56226?
CVE-2025-56226 has been classified as a medium severity vulnerability due to its potential to cause a memory leak.
2
How do I fix CVE-2025-56226?
To fix CVE-2025-56226, it is recommended to update to a patched version of libsndfile that is higher than 1.2.2.
3
What software is affected by CVE-2025-56226?
CVE-2025-56226 affects libsndfile versions up to and including 1.2.2.
4
What function is responsible for the vulnerability in CVE-2025-56226?
The memory leak vulnerability in CVE-2025-56226 is found in the mpeg_l3_encoder_init() function.
5
Are there any known exploits for CVE-2025-56226?
As of now, there are no publicly known exploits specifically targeting CVE-2025-56226.