PT-2026-106724 · Sezero · Libmikmod

·

CVE-2026-105839

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT doPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT module whose SLEN chunk wraps the 16-bit numtrk value, causing PBOD writes past allocated track pointers for crashes or code execution.

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105839

Affected Products

Libmikmod