Description
A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-09-30
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch ASAP
AI Analysis

Impact

The vulnerability is an integer overflow in the hexwave_init function of the stb_hexwave.h library. An attacker can manipulate the width and oversample arguments to cause the internal calculations to overflow, which can lead to memory corruption or execution of arbitrary code. The description states that remote exploitation is possible and a public exploit exists.

Affected Systems

Affecting the Nothings stb library, all versions up to commit 2c980bb59875b0d32144a71867fbdebb2f77cd20. No later versions are known to contain the fix; users must verify whether newer commits address the issue.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and while an EPSS score is not available, the existence of an exploitable public proof‑of‑concept raises concern. The vulnerability is not currently listed in the CISA KEV catalog, but the remote nature of the flaw and lack of a vendor response suggest it is a pressing threat. The attack vector is inferred to involve passing crafted numeric parameters to hexadecimal wave generation routines, potentially through user supplied data.

Generated by OpenCVE AI on September 30, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the stb library to a revision that includes the patch for the integer overflow in hexwave_init, ensuring the commit that resolves the issue is present.
  • If an update is not immediately available, validate any values passed to hexwave_init—particularly width and oversample—against safe bounds before invoking the function to mitigate the overflow.
  • Monitor the Nothings/stb GitHub issue tracker and security advisories for a released fix; apply it as soon as it becomes available to eliminate the remote exploitation risk.

Generated by OpenCVE AI on September 30, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title Nothings stb stb_hexwave.h hexwave_init integer overflow
First Time appeared Nothings
Nothings stb
Weaknesses CWE-189
CWE-190
CPEs cpe:2.3:a:nothings:stb:*:*:*:*:*:*:*:*
Vendors & Products Nothings
Nothings stb
References
Metrics cvssV2_0

{'score': 6.4, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-30T00:00:17.544Z

Reserved: 2026-09-29T17:08:45.132Z

Link: CVE-2026-102804

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T01:16:35.990

Modified: 2026-09-30T01:16:35.990

Link: CVE-2026-102804

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:00:07Z

Weaknesses