VDB
CVE-2026-29022
CVE-2026-29022
PUBLISHED
CVSS 6.800000190734863 MEDIUM
dr_libs version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.
EPSS 0.21% · 11.1th percentile
Risk Scores
CVSS 4.0
6.800000190734863
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.21%
11.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| mackron | dr_libs | 0, 0, 0 |
| mackron | dr_libs dr_wav.h | 0, 8a7258cc66b49387ad58cc5b81568982a3560d49, 0 |
Timeline
- Mar 3, 2026 CVE Published
- Mar 4, 2026 EPSS Score
- Mar 5, 2026 EPSS Score
- Mar 7, 2026 EPSS Score
- Mar 8, 2026 EPSS Score
- Mar 10, 2026 EPSS Score
- Mar 11, 2026 EPSS Score
- Mar 13, 2026 EPSS Score
- Mar 14, 2026 EPSS Score
- Mar 16, 2026 EPSS Score
- Mar 17, 2026 EPSS Score
- Mar 17, 2026 Coalition ESS Score
References
- https://github.com/mackron/dr_libs/commit/8a7258cc66b49387ad58cc5b81568982a3560d49 patch
- https://www.vulncheck.com/advisories/mackron-dr-libs-heap-buffer-overflow-via-wav-file third-party-advisory
- https://github.com/marlinkcyber/advisories/blob/main/advisories/MCSAID-2026-001-dr-libs-heap-overflow.md exploit
- https://github.com/mackron/dr_libs/issues/296 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-29022 advisory