Description
A vulnerability was determined in Konstanty Bialkowski libmodplug up to 0.8.9.1. This issue affects the function abc_add_gchord of the file src/load_abc.cpp of the component ABC Music Format Parser. This manipulation causes resource consumption. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Resource Consumption
Action: Apply Patch
AI Analysis

Impact

The flaw resides in the ABC Music Format parser of libmodplug, specifically within the abc_add_gchord routine in src/load_abc.cpp. Manipulating the behaviors of this routine can trigger excessive use of system resources, leading to a denial‑of‑service condition. The weakness is identified as a resource exhaustion problem (CWE‑400) and a potential improper handling of edge cases (CWE‑404). While no exploit code is publicly released, the description states that the attack can be initiated remotely, implying that a malicious ABC file could be supplied to a vulnerable system without local access.

Affected Systems

The affected software is Konstanty Bialkowski’s libmodplug library, version 0.8.9.1 or earlier. The vulnerability impacts any build that includes the ABC Music Format parser module and does not provide an updated code path to mitigate the resource consumption issue.

Risk and Exploitability

The CVSS score of 5.3 places the vulnerability in the medium severity range. EPSS data is not available, and the flaw is not catalogued in CISA’s KEV list, suggesting that there has been no confirmed, widespread exploitation to date. Nevertheless, an attacker who can supply a crafted ABC file over the network can trigger excessive CPU or memory usage, potentially disrupting service availability. The lack of available patch information increases the risk for systems that remain on the vulnerable version.

Generated by OpenCVE AI on October 11, 2026 at 13:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update libmodplug to a version newer than 0.8.9.1 that contains the fix for the abc_add_gchord routine.
  • If an update is not immediately possible, isolate the ABC file handling code behind stricter access controls or drop support for the ABC format in exposed services.
  • Monitor system resource usage for spikes corresponding to ABC file processing and apply process limits or cgroup quotas to contain any potential resource overuse.

Generated by OpenCVE AI on October 11, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Konstanty Bialkowski libmodplug up to 0.8.9.1. This issue affects the function abc_add_gchord of the file src/load_abc.cpp of the component ABC Music Format Parser. This manipulation causes resource consumption. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Title Konstanty Bialkowski libmodplug ABC Music Format load_abc.cpp abc_add_gchord resource consumption
First Time appeared Konstanty Bialkowski
Konstanty Bialkowski libmodplug
Weaknesses CWE-400
CWE-404
CPEs cpe:2.3:a:konstanty_bialkowski:libmodplug:*:*:*:*:*:*:*:*
Vendors & Products Konstanty Bialkowski
Konstanty Bialkowski libmodplug
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Konstanty Bialkowski Libmodplug
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T12:30:10.914Z

Reserved: 2026-10-10T15:48:56.120Z

Link: CVE-2026-108577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:13.230

Modified: 2026-10-11T13:17:13.230

Link: CVE-2026-108577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T13:30:19Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-404

    Improper Resource Shutdown or Release