Description
A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds write occurs in the vadpcm_read_coefs_be function of the EA SCHl parser within vgmstream. The function mis‑processes the entry/entries argument, allowing memory corruption that can be leveraged for remote exploitation, potentially enabling arbitrary code execution or data integrity compromise.

Affected Systems

Any installation of vgmstream up to revision 2117 that includes the EA SCHl parser is affected. The fix is available in the repository at commit ae37662ad626254ddd96ad69ac263792d7a92024.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available. The description states remote exploitation is possible, likely through a crafted audio file. While the vulnerability is not listed in CISA’s KEV catalog, its ability to cause arbitrary code execution warrants timely remediation.

Generated by OpenCVE AI on September 17, 2026 at 21:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update vgmstream to the patched revision (commit ae37662ad626254ddd96ad69ac263792d7a92024) or later.
  • Recompile any projects that embed vgmstream using the updated source to ensure buffer bounds checking is active.
  • If an immediate update is not possible, isolate the media processing component from untrusted input sources and restrict acceptance of audio files.

Generated by OpenCVE AI on September 17, 2026 at 21:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.
Title vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds write
First Time appeared Vgmstream
Vgmstream vgmstream
Weaknesses CWE-119
CWE-787
CPEs cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
Vendors & Products Vgmstream
Vgmstream vgmstream
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Vgmstream Vgmstream
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:45:01.168Z

Reserved: 2026-09-17T08:17:36.768Z

Link: CVE-2026-92880

cve-icon Vulnrichment

Updated: 2026-09-22T15:05:34.014Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T15:16:59.840

Modified: 2026-09-22T16:18:12.553

Link: CVE-2026-92880

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write