PT-2026-94374 · Git · Vgmstream

·

CVE-2026-92880

·

Published

2026-09-17

·

Updated

2026-09-22

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vgmstream versions prior to r2118
Description A weakness in the EA SCHl parser component allows for remote exploitation. The issue occurs within the vadpcm read coefs be() function located in the src/coding/vadpcm decoder.c file. Manipulation of the entry/entries argument leads to an out-of-bounds write, which is a condition where the program writes data past the end of the intended buffer.
Recommendations Install patch ae37662ad626254ddd96ad69ac263792d7a92024.

Exploit

Fix

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92880

Affected Products

Vgmstream