LiveActive security incident?Get immediate response
CVE Record

CVE-2026-37555: An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec.

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065.

HighCVSS 8.2Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2026-37555 is a high-severity libsndfile flaw in IMA ADPCM audio handling. A crafted WAV file can make the library calculate the wrong frame count, which may crash affected software or corrupt memory. Systems that process untrusted audio files automatically are the main concern.

Executive priority

Prioritize patching on systems that ingest external audio because impact includes service outage and possible memory corruption. Treat internet-facing media workflows as urgent, while internal-only or user-mediated processing can follow normal high-severity remediation timelines.

Technical view

In libsndfile 1.2.2, attacker-controlled WAV header values can trigger 32-bit integer overflow before assignment to a 64-bit frame count. The AIFF path was cast-fixed, but WAV and close paths were not, leaving heap buffer overflow or denial-of-service risk after an incomplete CVE-2022-33065 fix.

Likely exposure

Exposure is likely where libsndfile 1.2.2, or downstream packaged builds, process attacker-supplied WAV IMA ADPCM audio. Internet-facing upload, media conversion, scanning, or transcription pipelines have higher urgency than desktop-only use.

Exploitation context

The bundle does not show KEV listing or confirmed active exploitation. The issue is remotely reachable when a service accepts attacker-controlled audio, with low complexity and no privileges under the supplied CVSS vector.

Researcher notes

The core bug is CWE-190: samplesperblock and blocks are multiplied as ints before sf.frames assignment. The supplied example overflows 2,500,000,000 to a negative value, causing incorrect allocation or bounds assumptions. Evidence supports the root cause, but active exploitation is not established.

Mitigation direction

  • Apply vendor updates for libsndfile or affected OS packages.
  • For Red Hat systems, review and apply the listed RHSA advisories.
  • Limit or sandbox processing of untrusted WAV/AIFF files until patched.
  • Check non-Red Hat vendor guidance for fixed package availability.

Validation and detection

  • Inventory direct and transitive libsndfile usage across servers and containers.
  • Confirm whether deployed builds include libsndfile 1.2.2 or vulnerable downstream packages.
  • Identify services that accept or automatically process untrusted audio files.
  • Verify fixes include the WAV and close-path integer overflow correction.
  • Track Red Hat CVE, Bugzilla, CSAF, and errata status for your platforms.
Prepared
Confidence
high
Sources
12

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-190: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-37555 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
8.2 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

2CVSS vectors
5Timeline events
2ADP providers
21Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: partial

CVSS vector scores

2 official scores

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
8.2CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H3.94.2redhat-SADP
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6CISA-ADP

Vulnerability scoring details

Base CVSS 3.1 score

8.2High
CVSS 3.1 vector shape for CVE-2026-37555Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. ADP timelineredhat-SADP

    Made public.

  3. CVE publishedCVE Program

    The CVE record was published.

  4. ADP timelineredhat-SADP

    Reported to Red Hat.

  5. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
cvssV3_1other:ssvc
redhat-SADPlibsndfile: integer overflow in ima_reader_init()
other:Red Hat severity ratingcvssV3_1
  • 2026-04-29T17:00:55.901Z: Reported to Red Hat.
  • 2026-04-29T00:00:00.000Z: Made public.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-190 · source CWE mapping

Integer Overflow or Wraparound

Integer Overflow or Wraparound represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.