{"id":"UBUNTU-CVE-2026-29022","details":"dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h that allows memory corruption via crafted WAV files. Attackers can exploit a mismatch between sampleLoopCount validation in pass 1 and unconditional processing in pass 2 to overflow heap allocations with 36 bytes of attacker-controlled data through any drwav_init_*_with_metadata() call on untrusted input.","modified":"2026-09-16T14:02:03.933127801Z","published":"2026-03-03T20:16:00Z","related":["USN-8612-1"],"upstream":["CVE-2026-29022"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-29022"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-29022"},{"type":"REPORT","url":"https://github.com/mackron/dr_libs/commit/8a7258cc66b49387ad58cc5b81568982a3560d49"},{"type":"REPORT","url":"https://www.vulncheck.com/advisories/mackron-dr-libs-heap-buffer-overflow-via-wav-file"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8612-1"}],"affected":[{"package":{"name":"octave-ltfat","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/octave-ltfat?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.0+dfsg-1","2.1.1+dfsg-1","2.1.1+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_version":"2.1.1+dfsg-2","binary_name":"octave-ltfat"},{"binary_name":"octave-ltfat-common","binary_version":"2.1.1+dfsg-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"qtads","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/qtads?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.6-1"],"ecosystem_specific":{"binaries":[{"binary_name":"qtads","binary_version":"2.1.6-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"octave-ltfat","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/octave-ltfat?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.0+dfsg-4","2.2.0+dfsg-5","2.2.0+dfsg-7"],"ecosystem_specific":{"binaries":[{"binary_name":"octave-ltfat","binary_version":"2.2.0+dfsg-7"},{"binary_name":"octave-ltfat-common","binary_version":"2.2.0+dfsg-7"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"qtads","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/qtads?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.6-1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"qtads","binary_version":"2.1.6-1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"faudio","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/faudio?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["19.07-1","19.11-1","19.12-1","20.04-2"],"ecosystem_specific":{"binaries":[{"binary_name":"libfaudio0","binary_version":"20.04-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"octave-ltfat","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/octave-ltfat?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.1+dfsg-2","2.3.1+dfsg-2build1","2.3.1+dfsg-3","2.3.1+dfsg-3build1"],"ecosystem_specific":{"binaries":[{"binary_name":"octave-ltfat","binary_version":"2.3.1+dfsg-3build1"},{"binary_name":"octave-ltfat-common","binary_version":"2.3.1+dfsg-3build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"qtads","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/qtads?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.6-1.1","2.1.7-0.1","2.1.7-0.1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"qtads","binary_version":"2.1.7-0.1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"faudio","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/faudio?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["21.02-1","21.11-1","21.12-1","22.01-1","22.02-1"],"ecosystem_specific":{"binaries":[{"binary_version":"22.02-1","binary_name":"libfaudio0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"octave-ltfat","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/octave-ltfat?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.3.1+dfsg-8","2.3.1+dfsg-10","2.3.1+dfsg-10build1"],"ecosystem_specific":{"binaries":[{"binary_name":"octave-ltfat","binary_version":"2.3.1+dfsg-10build1"},{"binary_name":"octave-ltfat-common","binary_version":"2.3.1+dfsg-10build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"qtads","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/qtads?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.1.7-0.1build1"],"ecosystem_specific":{"binaries":[{"binary_name":"qtads","binary_version":"2.1.7-0.1build1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"dosbox-x","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/dosbox-x?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2023.10.06+dfsg-1","2024.03.01+dfsg-1build1","2024.03.01+dfsg-1build2"],"ecosystem_specific":{"binaries":[{"binary_version":"2024.03.01+dfsg-1build2","binary_name":"dosbox-x"},{"binary_name":"dosbox-x-data","binary_version":"2024.03.01+dfsg-1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"faudio","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/faudio?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["23.07+dfsg-1","23.08+dfsg-1","23.11+dfsg-1","24.02+dfsg-1","24.02+dfsg-1build1","24.02+dfsg-1build2"],"ecosystem_specific":{"binaries":[{"binary_name":"libfaudio0","binary_version":"24.02+dfsg-1build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"octave-ltfat","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/octave-ltfat?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.5.0+dfsg-2ubuntu1","2.6.0+dfsg-6ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"octave-ltfat","binary_version":"2.6.0+dfsg-6ubuntu1"},{"binary_name":"octave-ltfat-common","binary_version":"2.6.0+dfsg-6ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"qtads","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/qtads?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.4.0+dfsg-1","3.4.0+dfsg-1build1","3.4.0+dfsg-1build2","3.4.0+dfsg-1build3"],"ecosystem_specific":{"binaries":[{"binary_version":"3.4.0+dfsg-1build3","binary_name":"qtads"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"dosbox-x","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/dosbox-x?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2025.02.01+dfsg-1","2025.02.01+dfsg-3"],"ecosystem_specific":{"binaries":[{"binary_name":"dosbox-x","binary_version":"2025.02.01+dfsg-3"},{"binary_name":"dosbox-x-data","binary_version":"2025.02.01+dfsg-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"faudio","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/faudio?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["25.03+dfsg-2","25.04+dfsg-1","25.05+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_version":"25.05+dfsg-1","binary_name":"libfaudio0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"octave-ltfat","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/octave-ltfat?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.0+dfsg-6ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_version":"2.6.0+dfsg-6ubuntu2","binary_name":"octave-ltfat"},{"binary_name":"octave-ltfat-common","binary_version":"2.6.0+dfsg-6ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"qtads","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/qtads?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.4.0+dfsg-1build3"],"ecosystem_specific":{"binaries":[{"binary_name":"qtads","binary_version":"3.4.0+dfsg-1build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"roc-toolkit","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/roc-toolkit?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.4.0+dfsg-4ubuntu1","0.4.0+dfsg-5ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"libroc0.4","binary_version":"0.4.0+dfsg-5ubuntu1"},{"binary_version":"0.4.0+dfsg-5ubuntu1","binary_name":"roc-toolkit-tests"},{"binary_name":"roc-toolkit-tools","binary_version":"0.4.0+dfsg-5ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"dosbox-x","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/dosbox-x?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2025.02.01+dfsg-3","2025.10.07+dfsg-1","2025.12.01+dfsg-1","2026.01.02+dfsg-1","2026.01.02+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_name":"dosbox-x","binary_version":"2026.01.02+dfsg-2"},{"binary_version":"2026.01.02+dfsg-2","binary_name":"dosbox-x-data"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"faudio","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/faudio?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["25.05+dfsg-1","25.09+dfsg-1","25.12+dfsg-1","25.12+dfsg-2","26.01+dfsg-1"],"ecosystem_specific":{"binaries":[{"binary_version":"26.01+dfsg-1","binary_name":"libfaudio0"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"octave-ltfat","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/octave-ltfat?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.6.0+dfsg-6ubuntu2","2.6.0+dfsg-7","2.6.0+dfsg-7build1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.6.0+dfsg-7build1","binary_name":"octave-ltfat"},{"binary_version":"2.6.0+dfsg-7build1","binary_name":"octave-ltfat-common"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"qtads","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/qtads?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.4.0+dfsg-1build3","3.4.0+dfsg-2"],"ecosystem_specific":{"binaries":[{"binary_name":"qtads","binary_version":"3.4.0+dfsg-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}},{"package":{"name":"roc-toolkit","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/roc-toolkit?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.0+dfsg-5ubuntu3.1"}]}],"versions":["0.4.0+dfsg-5ubuntu1","0.4.0+dfsg-5ubuntu3"],"ecosystem_specific":{"binaries":[{"binary_version":"0.4.0+dfsg-5ubuntu3.1","binary_name":"libroc0.4"},{"binary_name":"roc-toolkit-tests","binary_version":"0.4.0+dfsg-5ubuntu3.1"},{"binary_version":"0.4.0+dfsg-5ubuntu3.1","binary_name":"roc-toolkit-tools"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-29022.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}