CVE-2026-92880

Source
https://cve.org/CVERecord?id=CVE-2026-92880
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92880.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-92880
Published
2026-09-17T15:00:12Z
Modified
2026-09-24T08:22:21Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds write
Details

A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.

Database specific
{
    "cna_assigner":  "VulDB",
    "cwe_ids":  [
        "CWE-119",
        "CWE-787"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92880.json"
}
References

Affected packages

Git / github.com/vgmstream/vgmstream

Affected ranges

Type
GIT
Repo
https://github.com/vgmstream/vgmstream
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "r2117"
        },
        {
            "last_affected":  "r2117"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

Other
r2117

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92880.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "61950491203349619542819047073684110605",
            "length":  424
        },
        "id":  "CVE-2026-92880-10d99fe5",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/coding/vadpcm_decoder.c",
            "function":  "vadpcm_read_coefs_be"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "221741655899341405355520873656546392911",
                "55010596707300793946803163126101891753",
                "250007935213284495856374148068038265277",
                "145199981610081947813644764322382782872",
                "270589024631504215031860228612840538844",
                "190939605965985965651449036493094516727",
                "225260035090917991029688070709497173701",
                "130225355172283258812440062378973838003",
                "257346637233878023777314346350643789729",
                "115724729695296889531713382721604932772"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92880-1beb7b82",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/coding/vadpcm_decoder.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "277919035690041846310118315747702608827",
                "191579810583570283803808898342780672284",
                "254811042427858936847494700657405935726",
                "36910391587684210834934834894162261835",
                "70144175419785209738034272747536287741",
                "39795347645260067342377428989831003454",
                "220676604697613284473193676532660606270",
                "189605501174611158398520266823696678613",
                "89048848195360174446663530295313470865",
                "249519714518561596723726149552150668134",
                "142067702656514483413847377251606091935",
                "1766340400062385431205303740956760637",
                "195327080898701314406218649410002094375",
                "324407869122832018574201868759715391835",
                "9804252359644321236787373588718787382",
                "138286893271057811087629221345634609143",
                "109177262425867329259507924992864640238",
                "98149895673777243802297339806656915866",
                "276724982101181025694146884556575863946",
                "218505817112042971847568815641468985994",
                "266299874133884625758235216685082700111",
                "335542039264217065079296989417461294694",
                "296150711073088609084390075015880658975"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92880-2b2396ce",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/meta/txtp_process.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "157031685117792206434395846209534741551",
            "length":  2865
        },
        "id":  "CVE-2026-92880-4b0340c2",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/meta/mus_acm.c",
            "function":  "parse_mus"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "197275797228318780486615163501610662271",
            "length":  1352
        },
        "id":  "CVE-2026-92880-52e3c036",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/meta/txtp_process.c",
            "function":  "make_group_random"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "292596885354562570734643441974552222465",
            "length":  1471
        },
        "id":  "CVE-2026-92880-69150f8f",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/coding/psx_decoder.c",
            "function":  "ps_find_padding"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "126366064877753608228551421847227752391",
                "256358577321216918515040422697826661095",
                "324911952815662409498315996761522187675",
                "229062097149129615251734303790004443621",
                "275491718711092959219307275697209147148",
                "716407587958725348062976086138125789",
                "275781060332014179518435619178840708848",
                "226846371991247407173102133515697672838",
                "279706029882529935789883004001216895768"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92880-8043c0ea",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/coding/psx_decoder.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "65973427816333387397513283991130181863",
            "length":  2114
        },
        "id":  "CVE-2026-92880-872c57cb",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/meta/awb.c",
            "function":  "init_vgmstream_awb_memory"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "134622419795886457617875045520913668775",
                "214650664164427520112557524052800536473",
                "326437658612950714337511886563505078742",
                "149368706715759937841290787272741104476",
                "154204545848386298322298961008299004146",
                "39882210791512762145354522531301775142",
                "118877436249817330260279694700750649654"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92880-abe1f893",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/meta/awb.c"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "227726273410518958710269584201445417286",
                "277609735454390599593020302753213892440",
                "201925238093322803516874118978487680824",
                "22797891440466018711134145158821279660",
                "207863274498105027805871801169732714857",
                "129667469129503579639724060674026198838",
                "41039891034359540688242295159842704115",
                "12616511260691492847972094834756637813",
                "285702210237374862010406241132795859283",
                "223326511966914072456640840773346854037",
                "128118525530024257850638119121653739636",
                "144892340657499280682089373220899369243"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-92880-e2bec889",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target":  {
            "file":  "src/meta/mus_acm.c"
        }
    }
]
vanir_signatures_modified
"2026-09-24T08:22:21Z"