Impact
The vulnerability is an integer overflow in the hexwave_init function of the stb_hexwave.h library. An attacker can manipulate the width and oversample arguments to cause the internal calculations to overflow, which can lead to memory corruption or execution of arbitrary code. The description states that remote exploitation is possible and a public exploit exists.
Affected Systems
Affecting the Nothings stb library, all versions up to commit 2c980bb59875b0d32144a71867fbdebb2f77cd20. No later versions are known to contain the fix; users must verify whether newer commits address the issue.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, and while an EPSS score is not available, the existence of an exploitable public proof‑of‑concept raises concern. The vulnerability is not currently listed in the CISA KEV catalog, but the remote nature of the flaw and lack of a vendor response suggest it is a pressing threat. The attack vector is inferred to involve passing crafted numeric parameters to hexadecimal wave generation routines, potentially through user supplied data.
OpenCVE Enrichment