StackRadar

CVE-2021-4156

High

Advisory

Published 23 Mar 2022In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.1
base score, highest
EPSS
0.018
77th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
61
of 17,781 indexed, latest versions
Container images
62
deployed by those charts
Fix available
1 of 1
affected package

libsndfile - security update

Carried by container images the latest versions of 61 of 17,781 indexed charts deploy, on 62 images.

Affected packageAffected versionsFixed inImages
libsndfiledeb1.0.25-7ubuntu2.2, 1.0.25-10ubuntu0.16.04.1, 1.0.25-10ubuntu0.16.04.2, 1.0.28-4+10 more1.0.25-7ubuntu2.2+esm4, 1.0.25-10ubuntu0.16.04.3+esm2, 1.0.28-4ubuntu0.18.04.2+esm2, 1.0.28-6+deb10u2+3 more62
OSV records
UBUNTU-CVE-2021-4156DLA-3126-1DLA-4402-1
Also known as
USN-5409-1, USN-7273-1

Charts affected

61 by stars
ChartLatestAffected imagesRadar Score
splashntppoolVerified publisher1.0.41 of 1See more

splash ntppool 1.0.4

1 of the 1 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
scrapinghub/splash:3.4.1a5f89bc84606
libsndfile@1.0.28-4ubuntu0.18.04.1
1.0.28-4ubuntu0.18.04.2+esm2

Open the chart page →

27,633
cdn-remoteopencord0.2.42 of 3See more

cdn-remote opencord 0.2.4

2 of the 3 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
libsndfile@1.0.28-4
1.0.28-4ubuntu0.18.04.2+esm2
omecproject/cdn-video-repo:1.0.0d59ccb138ffb
libsndfile@1.0.25-10ubuntu0.16.04.1
1.0.25-10ubuntu0.16.04.3+esm2

Open the chart page →

63,223
mcord-cdn-remoteopencord0.1.61 of 2See more

mcord-cdn-remote opencord 0.1.6

1 of the 2 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libsndfile@1.0.25-10ubuntu0.16.04.1
1.0.25-10ubuntu0.16.04.3+esm2

Open the chart page →

42,614
mcord-cdn-remote-freeopencord0.1.31 of 1See more

mcord-cdn-remote-free opencord 0.1.3

1 of the 1 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
omecproject/cdn-video-repo:remote-v3d59ccb138ffb
libsndfile@1.0.25-10ubuntu0.16.04.1
1.0.25-10ubuntu0.16.04.3+esm2

Open the chart page →

29,124
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
libsndfile@1.0.25-7ubuntu2.2
1.0.25-7ubuntu2.2+esm4

Open the chart page →

26,339
libretimepodzone-chartsVerified publisher0.4.12 of 9See more

libretime podzone-charts 0.4.1

2 of the 9 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
libsndfile@1.0.31-2
1.0.31-2+deb11u2
ghcr.io/libretime/libretime-playout:latest71a8706531aa
libsndfile@1.0.31-2
1.0.31-2+deb11u2

Open the chart page →

11,149
javareact-java0.1.01 of 1See more

java react-java 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
project2team4/react:latest3ff031a08887
libsndfile@1.0.28-7ubuntu0.1
1.0.28-7ubuntu0.3

Open the chart page →

15,520
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
libsndfile@1.0.31-2
1.0.31-2+deb11u2

Open the chart page →

6,026
node-redth0ths-helm-charts0.2.11 of 2See more

node-red th0ths-helm-charts 0.2.1

1 of the 2 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
th0th/node-red:4.0.3-debiand06fa39f7406
libsndfile@1.0.31-2
1.0.31-2+deb11u2

Open the chart page →

2,408
genievhdirkVerified publisher0.1.31 of 1See more

genie vhdirk 0.1.3

1 of the 1 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
stanfordoval/almond-server:latest1a63cdccedaf
libsndfile@1.0.28-6+deb10u1
1.0.28-6+deb10u2

Open the chart page →

3,129
playwright-synthetic-monitoringwork-adventure1.0.11 of 1See more

playwright-synthetic-monitoring work-adventure 1.0.1

1 of the 1 container images this version deploys carry CVE-2021-4156.

Container imageDigestPackageFixed in
workadventure/playwright-synthetic-monitoring:main92b664c2a06f
libsndfile@1.0.31-2ubuntu0.1
1.0.31-2ubuntu0.2

Open the chart page →

14,100

Container images carrying it

62 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/k8s-at-home/xteve:v2.2.0.200292b3614670f
libsndfile@1.0.28-7ubuntu0.1
1.0.28-7ubuntu0.3
1
ghcr.io/libretime/libretime-analyzer:latest3d5e236216ad
libsndfile@1.0.31-2
1.0.31-2+deb11u2
1
ghcr.io/libretime/libretime-playout:latest71a8706531aa
libsndfile@1.0.31-2
1.0.31-2+deb11u2
1
ghcr.io/linuxoid69/motion:4.7.0-0.1.0f0f000c3fc47
libsndfile@1.0.31-2
1.0.31-2+deb11u2
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
libsndfile@1.0.28-4ubuntu0.18.04.2
1.0.28-4ubuntu0.18.04.2+esm2
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
libsndfile@1.0.31-2
1.0.31-2+deb11u2
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
libsndfile@1.0.31-2
1.0.31-2+deb11u2
1
ghcr.io/savonet/liquidsoap:v2.0.19e08148e1055
libsndfile@1.0.31-2
1.0.31-2+deb11u2
1
ghcr.io/smarter-project/audio-client:v3.1.23c8375dc5487
libsndfile@1.0.28-7ubuntu0.1
1.0.28-7ubuntu0.3
1
ghcr.io/smarter-project/gstreamer:v1.0.25ecb16015aa8
libsndfile@1.0.28-7ubuntu0.1
1.0.28-7ubuntu0.3
1
ghcr.io/smarter-project/image-detector:v2.5.31dcca70c6446
libsndfile@1.0.28-7ubuntu0.1
1.0.28-7ubuntu0.3
1
quay.io/opsmxpublic/spin-sample-pipeline:v1.0.1c6a934439421
libsndfile@1.0.25-10ubuntu0.16.04.2
1.0.25-10ubuntu0.16.04.3+esm2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.