CVE-2026-92880Medium· 6.3▾ SunlitA weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 19.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92881Medium· 4.3A security vulnerability has been detected in vgmstream
CVE-2026-92879Medium· 4.3A security flaw has been discovered in vgmstream up to r2117
CVE-2026-86514Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-86515Medium· 4.3A security vulnerability has been detected in vgmstream up to r2117
CVE-2026-65334Medium· 4.3A memory corruption issue was addressed with improved state management
CVE-2026-84567Medium· 5.5The issue was addressed with improved memory handling