Thanks for updating the status of this! Would it be possible to change the ticket visibility to "Public" instead of "Private"?
Also, the crash occurs when attempting to convert the AIFF "poc" to "poc.wav" using the following command: ./sox poc poc.wav
SoX v14.4.2 vulnerable to a heap use-after-free condition after parsing AIFF file and calling sox_append_comments()