Description
A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be executed remotely. The name of the patch is ae37662ad626254ddd96ad69ac263792d7a92024. A patch should be applied to remediate this issue.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A security flaw in the AWB parser of vgmstream triggers a divide‑by‑zero error when the function init_vgmstream_awb_memory processes a crafted AWB file. The fault can cause the application to crash, resulting in a denial‑of‑service condition. The underlying weaknesses are identified as divide‑by‑zero processing (CWE‑369) and potential use‑after‑free or dangling reference (CWE‑404).

Affected Systems

The vulnerability affects all builds of the vgmstream library that include the original AWB parser code. Any deployment of vgmstream prior to the patch commit ae37662ad626254ddd96ad69ac263792d7a92024 is susceptible. No specific product version numbers are available, but the vulnerability is present until the code change is applied.

Risk and Exploitability

The CVSS base score of 5.3 places the flaw in the low‑moderate range. The EPSS score is not currently available, and the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. However, because the error can be triggered remotely by supplying a malicious AWB file and the patch is publicly available, administrators should treat the risk as moderate and act before a public exploit emerges.

Generated by OpenCVE AI on September 17, 2026 at 20:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a vgmstream version that contains the patch commit ae37662ad626254ddd96ad69ac263792d7a92024.
  • If immediate upgrade is not possible, permanently block or sandbox the handling of AWB files originating from untrusted sources to prevent the divide‑by‑zero condition.
  • Monitor for any new advisories or public exploits targeting this vulnerability and adjust access controls accordingly.

Generated by OpenCVE AI on September 17, 2026 at 20:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be executed remotely. The name of the patch is ae37662ad626254ddd96ad69ac263792d7a92024. A patch should be applied to remediate this issue.
Title vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero
First Time appeared Vgmstream
Vgmstream vgmstream
Weaknesses CWE-369
CWE-404
CPEs cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
Vendors & Products Vgmstream
Vgmstream vgmstream
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:N/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Vgmstream Vgmstream
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-23T16:19:30.188Z

Reserved: 2026-09-17T08:17:41.156Z

Link: CVE-2026-92881

cve-icon Vulnrichment

Updated: 2026-09-23T16:19:26.897Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T16:18:34.160

Modified: 2026-09-23T17:17:19.480

Link: CVE-2026-92881

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-369

    Divide By Zero

  • CWE-404

    Improper Resource Shutdown or Release