
CVE-2026-37555: libsndfile: IMA-ADPCM integer overflow (incomplete fix for CVE-2022-33065) https://www.openwall.com/lists/oss-security/2026/04/30/7 in WAV open path, leading to undersized buffer allocations and heap corruption during decoding. No patch has been released yet.
Post summary
The post announces a CVE-2026-37555 integer overflow in libsndfile that causes heap corruption, notes it’s an incomplete fix of a prior CVE, and indicates no patch is available yet.



