libsndfile through 1.2.2 has an oggvorbis.c vorbisanalysis_wrote out-of-bounds read.
{ "urgency": "not yet assigned" }