TagLib v2.3.2 announcement

Urs Fleisch urs.fleisch at gmail.com
Thu Aug 27 16:51:44 BST 2026


Hi all!

Since the release of TagLib v2.3.1, we had a lot of contributions, and
quite a few bugs have been fixed. Most of the commits address the prevention
of resource exhaustion, denial of service attacks and out of range conversions
by crafted input. I plan to release a bugfix release v2.3.2 next week.
As most supported audio formats are affected, it would be great if you could
test this before the release. The changes of the upcoming release can be
found on the master branch on GitHub.

A proposed change log entry could be

TagLib 2.3.2 (Sep 5, 2026)
==========================

 * MP3: Fix parsing of per-frame unsynchronized ID3v2 frames.
 * MP3: Accept iTunes ID3 frames with space padded ID3v2.2 ID.
 * MP4: More tolerant handling of `covr` atom with wrong flags.
 * MP4: Support additional codecs (AC3, DTS, EAC3, FLAC, Opus).
 * Ogg: Support Vorbis comments from a multiplexed stream.
 * WMA: Improve property interface for ASF files.
 * RIFF: Support RF64 and BW64 64-bit extensions.
 * Matroska: Fix file scanning with fast read style.
 * Matroska: Load attachment data lazily on demand.
 * Matroska: Read the segment title without audio properties.
 * Verify values parsed from files to prevent resource exhaustion, denial of
   service attacks and out of range conversions by crafted input for various
   file formats (AIFF, APE, DSDIFF, FLAC, MP3, MP4, MPC, Matroska, Ogg, SHN,
   WMA, XM).
 * Fix data races in lazily initialized shared caches, test thread safety.
 * Use `Requires.private` for zlib with `pkg-config`.

If I missed an important bug fix or something else which could make the
lives of TagLib users and distributors easier, please let us know!

Thanks!
Urs


More information about the taglib-devel mailing list