Impact
stb_v start_decoder routine where the allocation size for codebook multiplicands is truncated from a size_t to an int. This truncation causes the allocated buffer to be smaller than intended, enabling out‑of‑bounds writes on the heap when a decoder processes a malicious Ogg Vorbis file with large entries and dimension values. The resulting memory corruption can lead to crashes or, depending on the surrounding code, potentially allow an attacker to influence the execution state of the application.
Affected Systems
The vulnerability affects stb_vorbis version 1.22, as maintained by the nothings project.
Risk and Exploitability
This issue has a high severity CVSS score of 8.8, but the EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers who can supply a crafted Ogg Vorbis file to an application using stb_vorbis for decoding can trigger the out‑of‑bounds writes, potentially causing a crash or memory corruption without requiring elevated privileges.
OpenCVE Enrichment