CVE-2026-17512: reflection past the input¶
log_mel_spectrogram() reflects 200 samples from samples + 1 to pad a frame. The witnessed API input supplies only four float32 samples. With no n_samples >= 201 guard, std::reverse_copy continues beyond the caller's heap allocation and AddressSanitizer records a 4-byte read.
What the evidence supports¶
- The primitive is a heap out-of-bounds read, not a write.
- The minimal witness is 16 bytes / four raw float samples at the raw-sample API surface.
- Stock file-parser reachability was not established by that witness; the diagram states this boundary rather than promoting it into a file-format claim.
- Our submitted CWE was CWE-122; the assigner's CWE-125 better describes the observed read. The canonical ledger keeps both provenance sources.
- Our proposed score was 8.1 High; the assigner recorded CVSS v3.1 3.3 / v4.0 4.8.
Sources: the canonical CVE ledger and the public CRUCIBLE-2026-025 advisory.