Sorry, I mean source address (mad_stream.this_frame) + copied length (leftover) is inside the range of the target address (p->mp3_buffer)
Fixing ticket 325, possible integer overflow (addition) in sox-fmt.c function startread
Patch for Ticket 327
Memcpy-param-overlap in mp3-util.h
Integer Overflow in sox-fmt.c
If it is helpful, it has been assigned CVE-2019-8354
Stack-Buffer-Overflow in fft4g.c
Integer Overflow in xmalloc.h