CVE-2026-37555Disclosure(libsndfile_project / libsndfile)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch libsndfile_project libsndfile systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • libsndfile

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-29); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
libsndfile

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-04-29: 2Mentions · 2026-04-30: 1Mentions · 2026-06-16: 1Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-29: 2Technical Details · 2026-04-30: 1Technical Details · 2026-06-16: 104-2904-3006-16
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-292
Disclosure1Patch1
2026-04-301
Disclosure1
2026-06-161
Disclosure1
Full discourse4 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-37555: libsndfile: IMA-ADPCM integer overflow (incomplete fix for CVE-2022-33065) https://www.openwall.com/lists/oss-security/2026/04/30/7 in WAV open path, leading to undersized buffer allocations and heap corruption during decoding. No patch has been released yet.

    Post summary

    The post announces a CVE-2026-37555 integer overflow in libsndfile that causes heap corruption, notes it’s an incomplete fix of a prior CVE, and indicates no patch is available yet.

    01060333
    4.7K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 Alerta de segurança: libsndfile no #Mageia tem 3 CVEs críticas (CVE-2025-52194, CVE-2025-56226, CVE-2026-37555). Buffer overflow pode levar a execução remota de código. Saiba mais: -> http://tinyurl.com/kr76e3xf https://t.co/gjGV44jnG9

    Post summary

    The tweet alerts that Mageia’s libsndfile contains three critical CVEs involving a buffer overflow capable of remote code execution, but it provides no PoC, exploit code, patch details, or evidence of active exploitation.

    1000047
    1.5K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-37555 An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and clos… https://www.cve.org/CVERecord?id=CVE-2026-37555 ----- Traducción: CVE-2026-37555 Se … http://infoflow.cloud`

    Post summary

    The tweet references CVE-2026-37555, detailing an issue in the libsndfile 1.2.2 IMA ADPCM codec and its code path fix. No PoC, exploit, or patch release is mentioned.

    0000023
    74 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-37555 An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and clos… https://www.cve.org/CVERecord?id=CVE-2026-37555

    Post summary

    The CVE was identified in libsndfile 1.2.2 and a patch modifying the AIFF code path was referenced; no exploit or active use is reported.

    00000155
    57.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibsndfile_projectlibsndfile1.2.2--

Explore more