Impact
An out‑of‑bounds write occurs in the vadpcm_read_coefs_be function of the EA SCHl parser within vgmstream. The function mis‑processes the entry/entries argument, allowing memory corruption that can be leveraged for remote exploitation, potentially enabling arbitrary code execution or data integrity compromise.
Affected Systems
Any installation of vgmstream up to revision 2117 that includes the EA SCHl parser is affected. The fix is available in the repository at commit ae37662ad626254ddd96ad69ac263792d7a92024.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available. The description states remote exploitation is possible, likely through a crafted audio file. While the vulnerability is not listed in CISA’s KEV catalog, its ability to cause arbitrary code execution warrants timely remediation.
OpenCVE Enrichment