Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 17 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue. | |
| Title | vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds write | |
| First Time appeared |
Vgmstream
Vgmstream vgmstream |
|
| Weaknesses | CWE-119 CWE-787 |
|
| CPEs | cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vgmstream
Vgmstream vgmstream |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-17T15:00:12.927Z
Reserved: 2026-09-17T08:17:36.768Z
Link: CVE-2026-92880
No data.
Status : Received
Published: 2026-09-17T15:16:59.840
Modified: 2026-09-17T15:16:59.840
Link: CVE-2026-92880
No data.
OpenCVE Enrichment
No data.