MediaArea MediaInfoLib Channel Splitting Heap-Based Buffer Overflow Vulnerability

Vulnerability

A heap-based buffer overflow vulnerability has been identified in the Channel Splitting feature of MediaArea MediaInfoLib version 26.01. This vulnerability allows for arbitrary code execution by exploiting the way the library processes multi-channel audio in RIFF files. When a specially crafted .riff file is parsed, the library can be tricked into overwriting memory, potentially leading to execution of attacker-controlled code.

Impact

Exploitation of this vulnerability can result in a heap-based buffer overflow, allowing for arbitrary code execution.

Reproduction

The vulnerability can be reproduced by using a .riff file that has more than 2 audio channels, a bit depth of 20 bits, and a sampling rate of 48000 Hz. When this file is processed by MediaInfoLib version 26.01, the channel splitting functionality will incorrectly handle the audio data, leading to a heap buffer overflow.

Remediation

Users are advised to update to the patched version of MediaInfoLib, which is available on the project's GitHub page.

Added: May 20, 2026, 2:24 PM
Updated: May 20, 2026, 2:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
8.2
remediation
0.0
relevance
8.9
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.