Description
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is identified as ae37662ad626254ddd96ad69ac263792d7a92024. Applying a patch is advised to resolve this issue.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

A flaw in the parse_mus routine of vgmstream’s mus_acm.c leads to excessive resource consumption when processing specially crafted input. The vulnerability is an instance of improper input handling (CWE‑400) and a potential off‑by‑one error (CWE‑404). An attacker can exploit this by sending a crafted file to the affected binary, causing it to allocate large memory blocks or perform excessive CPU work, resulting in a denial of service.

Affected Systems

The issue affects the vgmstream media decoding library for all releases up to and including revision r2117. The affected product is the open‑source vgmstream binary; any deployments using these releases are vulnerable until the patch identified by commit ae37662ad626254ddd96ad69ac263792d7a92024 is applied.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity. The EPSS score is not available, so the exploitation probability cannot be quantified, but the lack of a known KEV listing suggests no widespread active exploitation at this time. Based on the description, the attack may be launched remotely, and no authentication is required. An attacker can trigger resource exhaustion without interacting with privileged accounts, causing service disruption for the target system.

Generated by OpenCVE AI on September 17, 2026 at 20:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update vgmstream to the patched version containing commit ae37662ad626254ddd96ad69ac263792d7a92024 or later
  • If an update is not possible immediately, run the playback service in a restricted environment that limits memory and CPU usage (e.g., using ulimit or container resource constraints)
  • Continuously monitor resource utilization and service logs for sudden spikes in memory or CPU, and restart or quarantine the service if abnormal patterns appear

Generated by OpenCVE AI on September 17, 2026 at 20:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is identified as ae37662ad626254ddd96ad69ac263792d7a92024. Applying a patch is advised to resolve this issue.
Title vgmstream mus_acm.c parse_mus resource consumption
First Time appeared Vgmstream
Vgmstream vgmstream
Weaknesses CWE-400
CWE-404
CPEs cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
Vendors & Products Vgmstream
Vgmstream vgmstream
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Vgmstream Vgmstream
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T15:36:51.641Z

Reserved: 2026-09-17T08:17:32.479Z

Link: CVE-2026-92879

cve-icon Vulnrichment

Updated: 2026-09-17T15:36:45.855Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T14:17:57.003

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-92879

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T20:45:16Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption

  • CWE-404

    Improper Resource Shutdown or Release