
CVE-2026-37555: libsndfile: IMA-ADPCM integer overflow (incomplete fix for CVE-2022-33065) https://www.openwall.com/lists/oss-security/2026/04/30/7 in WAV open path, leading to undersized buffer allocations and heap corruption during decoding. No patch has been released yet.
Post summary
The post announces CVE‑2026‑37555, detailing an integer overflow in libsndfile’s IMA‑ADPCM decoder that leads to heap corruption, and notes that no patch is yet available.
