GHSA-x46m-7mvp-6fvq · Severity: high — An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was...
An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.
Conclusion & alert: CVE-2026-37555 is rated Exploit Available (50/100): CVSS High severity, with low exploitation likelihood (EPSS 0.04%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-30 | — | 0.04% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-x46m-7mvp-6fvq · Severity: high — An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was...
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-37555 not yet assigned priority: Debian including 1 source packages (libsndfile), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): open 5. | https://security-tracker.debian.org/tracker/CVE-2026-37555 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2026-37555/ |
ubuntu
|
medium | CVE-2026-37555 medium priority: Ubuntu including 1 source packages (libsndfile), 9 status rows across 9 suites (bionic, focal, jammy, noble, questing, resolute, trusty, upstream, xenial): deferred 9. | https://ubuntu.com/security/CVE-2026-37555 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| libsndfile_project | libsndfile | 1.2.2 | cpe:2.3:a:libsndfile_project:libsndfile:1.2.2:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://gist.github.com/sgInnora/a5f5c19e4bf6f4fb74fab7b0ef2bfcc1 | Exploit Third Party Advisory |
| https://github.com/libsndfile/libsndfile/commit/9a829113c88a51e57c1e46473e90609e4b7df151 | Patch |
| https://github.com/libsndfile/libsndfile/issues/833 | Issue Tracking |