Executive brief
A vulnerability was found in libsndfile, a widely used library for processing audio files like WAV and AIFF. By tricking a user or automated system into opening a specially crafted audio file, an attacker can cause the application to crash or behave unexpectedly. This could lead to a denial of service, impacting the availability of audio processing workflows or applications that rely on this library.
Technical details
An integer overflow exists in src/ima_adpcm.c within libsndfile versions up to 1.2.2. The vulnerability occurs because the multiplication of 'samplesperblock' and 'blocks' (both 32-bit signed integers) is performed without a 64-bit cast in the WAV/W64 reader initialization and close paths. When the product exceeds INT_MAX, it wraps to a negative value, which is then assigned to the 64-bit frame count (sf.frames). This incorrect frame count can lead to out-of-bounds heap memory access or application crashes. This issue represents an incomplete fix for CVE-2022-33065, which only addressed the AIFF code path. Patches are available in the libsndfile repository and via various Linux distribution updates.
Affected products
- libsndfile libsndfile <= 1.2.2
- Red Hat Enterprise Linux 8, 10
Timeline
- 2026-04-02: disclosed: Reported by Innora Security Research
- 2026-04-29: advisory: NVD publication date
- 2026-05-20: patched: Red Hat released security updates (RHSA-2026:19559)
References
- https://gist.github.com/sgInnora/a5f5c19e4bf6f4fb74fab7b0ef2bfcc1
- https://github.com/libsndfile/libsndfile/commit/9a829113c88a51e57c1e46473e90609e4b7df151
- https://github.com/libsndfile/libsndfile/issues/833
- https://access.redhat.com/errata/RHSA-2026:19559
- https://access.redhat.com/errata/RHSA-2026:19560
- https://access.redhat.com/errata/RHSA-2026:19610
- https://access.redhat.com/errata/RHSA-2026:23221