← Back to CVE List
CVE-2026-92880NVD
Vulnerability Summary
A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.
CVSS v4.0 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 6.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- n/a vgmstream >= r2117
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/406346
- https://vuldb.com/vuln/406346/cti
- https://vuldb.com/cve/CVE-2026-92880
- https://vuldb.com/submit/942161
- https://github.com/vgmstream/vgmstream/issues/1994
- https://github.com/vgmstream/vgmstream/pull/2008
- https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024
- https://github.com/vgmstream/vgmstream/