


Perceptive Security
SOC/SIEM Consultancy

Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows …
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 21:01:38
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
Music Player Daemon (MPD) before version 0.24.11 contains a critical stack buffer overflow vulnerability in the pcm_unpack_24be function. The vulnerability allows unauthenticated attackers to corrupt stack memory through an off-by-one write in the PCM decoder plugin. Attackers can exploit this by issuing two MPD commands referencing a malicious HTTP audio source, causing the unpack loop to write 1366 entries into a 1365-entry buffer. This overwrites four bytes past the array boundary with three attacker-controlled bytes from an HTTP response body. The exploitation can result in daemon termination or potential code execution, making this a high-severity vulnerability affecting audio streaming infrastructure.
Technical details
Mitigation steps:
Affected products:
Music Player Daemon (MPD)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-49127
https://github.com/MusicPlayerDaemon/MPD/commit/59911028c020f84bc2e669da6a1ef88121301274
https://github.com/MusicPlayerDaemon/MPD/issues/2485
https://github.com/MusicPlayerDaemon/MPD/releases/tag/v0.24.11
https://raw.githubusercontent.com/MusicPlayerDaemon/MPD/v0.24.11/NEWS
https://www.musicpd.org/news/2026/05/mpd-0-24-11-released/
https://www.vulncheck.com/advisories/music-player-daemon-stack-buffer-overflow-via-pcm-unpack-24be
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
