### [CVE-2022-48363](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-48363) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer. ### POC #### Reference No PoCs from references. #### Github - https://github.com/1-tong/vehicle_cves - https://github.com/Vu1nT0tal/Vehicle-Security - https://github.com/VulnTotal-Team/Vehicle-Security - https://github.com/VulnTotal-Team/vehicle_cves