VYPR
High severity7.3NVD Advisory· Published Mar 3, 2026· Updated Jul 14, 2026

CVE-2026-29022

CVE-2026-29022

Description

dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Mackron/Dr Libscpe-rescue3 versions
    0+ 2 more
    • (no CPE)range: 0
    • (no CPE)range: <=0.14.4
    • cpe:2.3:a:mackron:dr_libs:*:*:*:*:*:*:*:*range: <=0.14.4

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.