Bug 2444194 (CVE-2026-29022) - CVE-2026-29022 dr_libs: dr_libs: Heap buffer overflow via crafted WAV files
Summary: CVE-2026-29022 dr_libs: dr_libs: Heap buffer overflow via crafted WAV files
Keywords:
Status: NEW
Alias: CVE-2026-29022
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2444311 2444313 2444308 2444310 2444312
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-03-03 20:01 UTC by OSIDB Bzimport
Modified: 2026-03-04 05:32 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-03-03 20:01:31 UTC
dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.


Note You need to log in before you can comment on or make changes to this bug.