PT-2026-94342 · Vgmstream · Vgmstream

·

CVE-2026-92879

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions vgmstream versions prior to r2118
Description A security flaw exists that allows for remote resource consumption. The issue is located within the parse mus() function of the src/meta/mus acm.c file.
Recommendations Apply patch ae37662ad626254ddd96ad69ac263792d7a92024 to resolve the issue. As a temporary workaround, consider restricting the use of the parse mus() function until the patch is applied.

Exploit

Fix

Improper Resource Release

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92879

Affected Products

Vgmstream