No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 18 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 18 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state. | |
| Title | libmodplug <= 0.8.9.1 - Out-of-Bounds Read in pat_smplooped via Crafted MIDI File | |
| First Time appeared |
Konstanty Bialkowski
Konstanty Bialkowski libmodplug |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:2.3:a:konstanty_bialkowski:libmodplug:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Konstanty Bialkowski
Konstanty Bialkowski libmodplug |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T15:36:11.749Z
Reserved: 2026-08-18T14:53:24.138Z
Link: CVE-2026-75904
Updated: 2026-08-18T15:36:08.576Z
Status : Received
Published: 2026-08-18T16:18:22.540
Modified: 2026-08-18T16:18:22.540
Link: CVE-2026-75904
No data.
OpenCVE Enrichment
Updated: 2026-08-18T17:30:15Z