Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state. | |
| Title | libmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI File | |
| First Time appeared |
Konstanty Bialkowski
Konstanty Bialkowski libmodplug |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:konstanty_bialkowski:libmodplug:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Konstanty Bialkowski
Konstanty Bialkowski libmodplug |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T15:36:11.749Z
Reserved: 2026-08-18T14:53:24.138Z
Link: CVE-2026-75904
Updated: 2026-08-18T15:36:08.576Z
Status : Received
Published: 2026-08-18T16:18:22.540
Modified: 2026-08-18T16:18:22.540
Link: CVE-2026-75904
No data.
OpenCVE Enrichment
No data.