UBUNTU-CVE-2026-29022
dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.
UBUNTU-CVE-2026-29022
Description
dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.
CVSS v4.0
Affected software
pkg:deb/ubuntu/[email protected]+dfsg-2?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]+dfsg-7?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]+dfsg-3build1?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+dfsg-10build1?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+dfsg-1build2?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+dfsg-1build2?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+dfsg-6ubuntu1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+dfsg-1build3?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+dfsg-3?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+dfsg-1?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+dfsg-6ubuntu2?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+dfsg-1build3?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+dfsg-5ubuntu1?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+dfsg-2?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]+dfsg-1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]+dfsg-7build1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]+dfsg-2?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]+dfsg-5ubuntu3?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-29022
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:18.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 4.0
Threat ID: 6a5b62702d1edb114c88d97c
Added to database: 07/18/2026, 11:24:32 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.