CVE-2026-3394 PUBLISHED

jarikomppa soloud WAV File soloud_wav.cpp loadwav memory corruption

Assigner: VulDB
Reserved: 28.02.2026 Published: 01.03.2026 Updated: 01.03.2026

A vulnerability was detected in jarikomppa soloud up to 20200207. This affects the function SoLoud::Wav::loadwav of the file src/audiosource/wav/soloud_wav.cpp of the component WAV File Parser. Performing a manipulation results in memory corruption. The attack must be initiated from a local position. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.8

Product Status

Vendor jarikomppa
Product soloud
Versions
  • Version 20200207 is affected

Credits

  • Oneafter (VulDB User) reporter

References

Problem Types

  • Memory Corruption CWE