CVE 8.8 HIGH

Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be_CVE-2026-49127

8.8 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N

Description

Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing a malicious HTTP audio source to cause the unpack loop to write 1366 entries into a 1365-entry buffer, overwriting four bytes past the array boundary with three attacker-controlled bytes from an HTTP response body, resulting in daemon termination or potential code execution.

AI Analysis

Stack buffer overflow vulnerability in Music Player Daemon (MPD) before version 0.24.11, allowing unauthenticated attackers to corrupt stack memory and potentially execute code.

Basic Information

ID CVE-2026-49127
Source VulnCheck
Published May 28, 2026 at 18:59
Modified May 28, 2026 at 20:40

Affected Product

Vendor MusicPlayerDaemon
Product MPD
Affected Versions MusicPlayerDaemon MPD 0

CWE Classification

AI Assessment

AI Score 8.8 / 10
AI Severity High
Vendor MusicPlayerDaemon
Product Music Player Daemon (MPD)
Version < 0.24.11

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.