PT-2026-106724 · Sezero · Libmikmod

·

CVE-2026-105839

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT doPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT module whose SLEN chunk wraps the 16-bit numtrk value, causing PBOD writes past allocated track pointers for crashes or code execution.

Correção

Integer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-105839

Produtos afetados

Libmikmod