Junglewise Threat Intelligence

CVE-2026-37555: libsndfile integer overflow in IMA ADPCM codec

CVE-2026-37555 · Severity: high · CVSS 7.5 · Published 2026-04-29

Technologies: Red Hat Enterprise Linux. Vendors: Red Hat.

Executive brief

A vulnerability was found in libsndfile, a widely used library for processing audio files like WAV and AIFF. By tricking a user or automated system into opening a specially crafted audio file, an attacker can cause the application to crash or behave unexpectedly. This could lead to a denial of service, impacting the availability of audio processing workflows or applications that rely on this library.

Technical details

An integer overflow exists in src/ima_adpcm.c within libsndfile versions up to 1.2.2. The vulnerability occurs because the multiplication of 'samplesperblock' and 'blocks' (both 32-bit signed integers) is performed without a 64-bit cast in the WAV/W64 reader initialization and close paths. When the product exceeds INT_MAX, it wraps to a negative value, which is then assigned to the 64-bit frame count (sf.frames). This incorrect frame count can lead to out-of-bounds heap memory access or application crashes. This issue represents an incomplete fix for CVE-2022-33065, which only addressed the AIFF code path. Patches are available in the libsndfile repository and via various Linux distribution updates.

Affected products

  • libsndfile libsndfile <= 1.2.2
  • Red Hat Enterprise Linux 8, 10

Timeline

  • 2026-04-02: disclosed: Reported by Innora Security Research
  • 2026-04-29: advisory: NVD publication date
  • 2026-05-20: patched: Red Hat released security updates (RHSA-2026:19559)

References