Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-37555

Опубликовано: 29 апр. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.

A flaw was found in the libsndfile library. An integer overflow in the IMA ADPCM codec can occur when a specially crafted WAV audio file is processed, specifically with malicious samplesperblock and blocks values. This can lead to a heap-based buffer overflow, causing a crash to the application linked to the library and memory corruption.

Отчет

To exploit this issue, an attacker needs to be able to process a malicious WAV file with an application linked to the libsndfile library. Default Red Hat Enterprise Linux security features, including SELinux enforcement, Address Space Layout Randomization (ASLR) and NX (No-Execute) stack protection, significantly increase the difficulty of achieving arbitrary code execution, limiting the impact of this vulnerability. Due to these reasons, this flaw has been rated with an important severity.

Меры по смягчению последствий

Do not process untrusted WAV files with the libsndfile library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6libsndfileOut of support scope
Red Hat Enterprise Linux 7libsndfileOut of support scope
Red Hat Enterprise Linux 10libsndfileFixedRHSA-2026:1956020.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportlibsndfileFixedRHSA-2026:2509210.06.2026
Red Hat Enterprise Linux 8libsndfileFixedRHSA-2026:1955920.05.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportlibsndfileFixedRHSA-2026:2519711.06.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnlibsndfileFixedRHSA-2026:2519711.06.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportlibsndfileFixedRHSA-2026:2519811.06.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnlibsndfileFixedRHSA-2026:2519811.06.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicelibsndfileFixedRHSA-2026:2522711.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2463856libsndfile: integer overflow in ima_reader_init()

EPSS

Процентиль: 40%
0.00504
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.

CVSS3: 7.5
nvd
3 месяца назад

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.

CVSS3: 7.5
msrc
3 месяца назад

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.

CVSS3: 7.5
debian
3 месяца назад

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF ...

rocky
2 месяца назад

Important: libsndfile security update

EPSS

Процентиль: 40%
0.00504
Низкий

8.2 High

CVSS3