Description
stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.
Published: 2026-09-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Heap Buffer Overflow
Action: Patch
AI Analysis

Impact

stb_v start_decoder routine where the allocation size for codebook multiplicands is truncated from a size_t to an int. This truncation causes the allocated buffer to be smaller than intended, enabling out‑of‑bounds writes on the heap when a decoder processes a malicious Ogg Vorbis file with large entries and dimension values. The resulting memory corruption can lead to crashes or, depending on the surrounding code, potentially allow an attacker to influence the execution state of the application.

Affected Systems

The vulnerability affects stb_vorbis version 1.22, as maintained by the nothings project.

Risk and Exploitability

This issue has a high severity CVSS score of 8.8, but the EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers who can supply a crafted Ogg Vorbis file to an application using stb_vorbis for decoding can trigger the out‑of‑bounds writes, potentially causing a crash or memory corruption without requiring elevated privileges.

Generated by OpenCVE AI on September 15, 2026 at 20:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a newer release of stb_vorbis where the allocation size truncation has been fixed.
  • Validate the size and dimension fields of incoming Ogg Vorbis data and enforce reasonable limits before passing them to the decoder.
  • Run Vorbis decoding in a sandboxed environment to contain any potential memory corruption or crashes.

Generated by OpenCVE AI on September 15, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.
Title stb_vorbis through 1.22 heap buffer overflow via codebook multiplicands
First Time appeared Stb Vorbis Project
Stb Vorbis Project stb Vorbis
Weaknesses CWE-787
CPEs cpe:2.3:a:stb_vorbis_project:stb_vorbis:*:*:*:*:*:*:*:*
Vendors & Products Stb Vorbis Project
Stb Vorbis Project stb Vorbis
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Stb Vorbis Project Stb Vorbis
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:42.371Z

Reserved: 2026-09-11T10:52:56.669Z

Link: CVE-2026-89266

cve-icon Vulnrichment

Updated: 2026-09-20T00:31:00.808Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T00:17:06.440

Modified: 2026-09-24T21:08:55.030

Link: CVE-2026-89266

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:30:10Z

Weaknesses