Description
A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Remote Denial of Service
Action: Patch
AI Analysis

Impact

The flaw lies in the function decode_ms_ima of vgmstream's Microsoft IMA Decoder module. By feeding specially crafted audio data, an attacker can trigger a divide‑by‑zero exception during decoding, causing the application to crash. This weakness is identified as integer division by zero (CWE-369) and a failure to properly handle resource shutdown (CWE-404). While no code execution is implied directly, the resulting crash constitutes a denial‑of‑service condition that can be triggered over the network.

Affected Systems

vgmstream, a multimedia processing library, is affected in all releases up to revision r2117. The vulnerability is present globally in the vgmstream code base, and no later patches are included in the current release cycle objects. Users of the vgmstream library who process Microsoft IMA encoded audio prior to r2118 are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 rates this issue as moderate severity, and the EPSS score is currently unavailable, suggesting limited exploitation likelihood. Because the attack payload is a crafted audio file, an attacker must deliver the file over the network or local file system to trigger the crash. No publicly documented exploits exist and the vulnerability is not listed in CISA's KEV catalog, indicating a lower threat level compared to active, remote code execution bugs.

Generated by OpenCVE AI on October 5, 2026 at 09:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade vgmstream to revision r2118 or later, which contains the fix in the Microsoft IMA Decoder module.
  • If an immediate update is not possible, ensure that only trusted audio sources are fed into the library and quarantine any unverified files before decoding.
  • Add an application‑level guard to detect anomalously large or malformed IMA frames and abort decoding before reaching the division operation, thus preventing the divide‑by‑zero exception.

Generated by OpenCVE AI on October 5, 2026 at 09:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely.
Title vgmstream Microsoft IMA Decoder ima_decoder.c decode_ms_ima divide by zero
First Time appeared Vgmstream
Vgmstream vgmstream
Weaknesses CWE-369
CWE-404
CPEs cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
Vendors & Products Vgmstream
Vgmstream vgmstream
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Vgmstream Vgmstream
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T07:45:12.711Z

Reserved: 2026-10-04T17:37:14.702Z

Link: CVE-2026-105250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T08:17:15.610

Modified: 2026-10-05T08:17:15.610

Link: CVE-2026-105250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T09:30:10Z

Weaknesses
  • CWE-369

    Divide By Zero

  • CWE-404

    Improper Resource Shutdown or Release