{"id":"CVE-2026-92880","published":"2026-09-17T15:16:59.840","lastModified":"2026-09-22T16:18:12.553","description":"A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.","cvssScore":6.3,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","cwes":["CWE-119","CWE-787"],"vendors":[],"products":[],"references":[{"url":"https://github.com/vgmstream/vgmstream/","tags":[]},{"url":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","tags":[]},{"url":"https://github.com/vgmstream/vgmstream/issues/1994","tags":[]},{"url":"https://github.com/vgmstream/vgmstream/pull/2008","tags":[]},{"url":"https://vuldb.com/cve/CVE-2026-92880","tags":[]},{"url":"https://vuldb.com/submit/942161","tags":[]},{"url":"https://vuldb.com/vuln/406346","tags":[]},{"url":"https://vuldb.com/vuln/406346/cti","tags":[]}],"exploitRefs":[{"url":"https://github.com/vgmstream/vgmstream/","tags":[]},{"url":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","tags":[]},{"url":"https://github.com/vgmstream/vgmstream/issues/1994","tags":[]},{"url":"https://github.com/vgmstream/vgmstream/pull/2008","tags":[]}],"hasPoc":true,"ai":null}