Impact
A security flaw in the AWB parser of vgmstream triggers a divide‑by‑zero error when the function init_vgmstream_awb_memory processes a crafted AWB file. The fault can cause the application to crash, resulting in a denial‑of‑service condition. The underlying weaknesses are identified as divide‑by‑zero processing (CWE‑369) and potential use‑after‑free or dangling reference (CWE‑404).
Affected Systems
The vulnerability affects all builds of the vgmstream library that include the original AWB parser code. Any deployment of vgmstream prior to the patch commit ae37662ad626254ddd96ad69ac263792d7a92024 is susceptible. No specific product version numbers are available, but the vulnerability is present until the code change is applied.
Risk and Exploitability
The CVSS base score of 5.3 places the flaw in the low‑moderate range. The EPSS score is not currently available, and the issue is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. However, because the error can be triggered remotely by supplying a malicious AWB file and the patch is publicly available, administrators should treat the risk as moderate and act before a public exploit emerges.
OpenCVE Enrichment