PT-2026-35949 · Unknown+1 · Libsndfile+1

·

CVE-2026-37555

·

Published

2026-04-29

·

Updated

2026-08-24

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions libsndfile version 1.2.2
Description An integer overflow exists in the IMA ADPCM codec within the WAV and close code paths. When the product of samplesperblock and blocks exceeds the maximum value of a 32-bit signed integer (INT MAX), a multiplication overflow occurs before the result is assigned to sf.frames. Because both samplesperblock and blocks are attacker-controlled values sourced from the WAV file header, this can lead to an incorrect frame count, resulting in a heap buffer overflow or denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:19559
ALSA-2026:19560
ALSA-2026:19610
AZL-85457
CVE-2026-37555
ECHO-784A-04F4-95B4
OESA-2026-2711
OESA-2026-2712
OPENSUSE-SU-2026:10730-1
OPENSUSE-SU-2026:20787-1
RHSA-2026:19559
RHSA-2026:19560
RHSA-2026:19610
RHSA-2026:23221
RHSA-2026:23222
RHSA-2026:23223
RHSA-2026:25092
RHSA-2026:25197
RHSA-2026:25198
RHSA-2026:25227
SUSE-SU-2026:1968-1
SUSE-SU-2026:1969-1
SUSE-SU-2026:21826-1

Affected Products

Rocky Linux
Libsndfile