CVE-2026-29022Disclosure(mackron / dr_libs)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch mackron dr_libs systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dr_libs

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-03); latest day: 2
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dr_libs

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-03: 3Mentions · 2026-03-13: 2Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-13: 1Technical Details · 2026-03-03: 2Technical Details · 2026-03-13: 103-0303-13
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-033
Disclosure2General1
2026-03-132
Disclosure1Patch1
Full discourse5 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Just a heads up for the Fedora and open-source gaming community: CVE-2026-29022 has been patched in easyrpg-player for #Fedora 43. Read more: 👉 https://tinyurl.com/8nhzu8v6 #Security https://t.co/AKecY2AZog

    Post summary

    The tweet announces that CVE‑2026‑29022 has been patched in easyrpg‑player for Fedora 43, offering a link for more information.

    0000051
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    The #Fedora 42 EasyRPG Player update is a masterclass in dependency management. A single audio library (dr_wav) posed a critical code execution risk (CVE-2026-29022). Read more: 👉 https://tinyurl.com/6csn36wc #Security https://t.co/oaeiSA2wgE

    Post summary

    The tweet announces a critical code execution vulnerability (CVE-2026-29022) in Fedora 42's EasyRPG Player caused by the dr_wav audio library and directs readers to additional details.

    0000049
    1.3K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29022 Heap Buffer Overflow in dr_libs WAV Metadata Parsing Enables Memory Corruption https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29022

    Post summary

    A heap buffer overflow vulnerability (CVE-2026-29022) in dr_libs WAV metadata parsing has been disclosed, allowing memory corruption.

    0000037
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29022 dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav… https://www.cve.org/CVERecord?id=CVE-2026-29022

    Post summary

    The CVE-2026-29022 details a heap buffer overflow in dr_libs before version 0.14.4, which is fixed in a specific commit.

    00000155
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-29022 Intel Report: https://ift.tt/HVFjIGA

    Post summary

    A brief alert links to an Intel report on CVE-2026-29022 but provides no further technical or mitigation details.

    0000032
    342 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmackrondr_libs---

Explore more