{"id":"CVE-2026-92880","summary":"vgmstream EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be out-of-bounds write","details":"A weakness has been identified in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write. Remote exploitation of the attack is possible. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is suggested to install a patch to address this issue.","modified":"2026-09-24T08:22:21.806596Z","published":"2026-09-17T15:00:12.927Z","database_specific":{"cwe_ids":["CWE-119","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92880.json","cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/vgmstream/vgmstream/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92880.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92880"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-92880"},{"type":"ADVISORY","url":"https://vuldb.com/submit/942161"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/406346"},{"type":"REPORT","url":"https://github.com/vgmstream/vgmstream/issues/1994"},{"type":"REPORT","url":"https://vuldb.com/vuln/406346/cti"},{"type":"FIX","url":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024"},{"type":"FIX","url":"https://github.com/vgmstream/vgmstream/pull/2008"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vgmstream/vgmstream","events":[{"introduced":"71e2361042531fe767fb98300cf8c1ee95e539a0"},{"fixed":"ae37662ad626254ddd96ad69ac263792d7a92024"}],"database_specific":{"extracted_events":[{"introduced":"r2117"},{"last_affected":"r2117"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["r2117"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92880.json","vanir_signatures_modified":"2026-09-24T08:22:21Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/coding/vadpcm_decoder.c","function":"vadpcm_read_coefs_be"},"deprecated":false,"digest":{"function_hash":"61950491203349619542819047073684110605","length":424},"id":"CVE-2026-92880-10d99fe5"},{"signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/coding/vadpcm_decoder.c"},"deprecated":false,"digest":{"line_hashes":["221741655899341405355520873656546392911","55010596707300793946803163126101891753","250007935213284495856374148068038265277","145199981610081947813644764322382782872","270589024631504215031860228612840538844","190939605965985965651449036493094516727","225260035090917991029688070709497173701","130225355172283258812440062378973838003","257346637233878023777314346350643789729","115724729695296889531713382721604932772"],"threshold":0.9},"id":"CVE-2026-92880-1beb7b82","signature_type":"Line"},{"source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/txtp_process.c"},"deprecated":false,"digest":{"line_hashes":["277919035690041846310118315747702608827","191579810583570283803808898342780672284","254811042427858936847494700657405935726","36910391587684210834934834894162261835","70144175419785209738034272747536287741","39795347645260067342377428989831003454","220676604697613284473193676532660606270","189605501174611158398520266823696678613","89048848195360174446663530295313470865","249519714518561596723726149552150668134","142067702656514483413847377251606091935","1766340400062385431205303740956760637","195327080898701314406218649410002094375","324407869122832018574201868759715391835","9804252359644321236787373588718787382","138286893271057811087629221345634609143","109177262425867329259507924992864640238","98149895673777243802297339806656915866","276724982101181025694146884556575863946","218505817112042971847568815641468985994","266299874133884625758235216685082700111","335542039264217065079296989417461294694","296150711073088609084390075015880658975"],"threshold":0.9},"id":"CVE-2026-92880-2b2396ce","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/mus_acm.c","function":"parse_mus"},"deprecated":false,"digest":{"function_hash":"157031685117792206434395846209534741551","length":2865},"id":"CVE-2026-92880-4b0340c2"},{"digest":{"function_hash":"197275797228318780486615163501610662271","length":1352},"id":"CVE-2026-92880-52e3c036","signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/txtp_process.c","function":"make_group_random"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/coding/psx_decoder.c","function":"ps_find_padding"},"deprecated":false,"digest":{"function_hash":"292596885354562570734643441974552222465","length":1471},"id":"CVE-2026-92880-69150f8f"},{"deprecated":false,"digest":{"line_hashes":["126366064877753608228551421847227752391","256358577321216918515040422697826661095","324911952815662409498315996761522187675","229062097149129615251734303790004443621","275491718711092959219307275697209147148","716407587958725348062976086138125789","275781060332014179518435619178840708848","226846371991247407173102133515697672838","279706029882529935789883004001216895768"],"threshold":0.9},"id":"CVE-2026-92880-8043c0ea","signature_type":"Line","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/coding/psx_decoder.c"}},{"digest":{"function_hash":"65973427816333387397513283991130181863","length":2114},"id":"CVE-2026-92880-872c57cb","signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"function":"init_vgmstream_awb_memory","file":"src/meta/awb.c"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/awb.c"},"deprecated":false,"digest":{"line_hashes":["134622419795886457617875045520913668775","214650664164427520112557524052800536473","326437658612950714337511886563505078742","149368706715759937841290787272741104476","154204545848386298322298961008299004146","39882210791512762145354522531301775142","118877436249817330260279694700750649654"],"threshold":0.9},"id":"CVE-2026-92880-abe1f893","signature_type":"Line"},{"id":"CVE-2026-92880-e2bec889","signature_type":"Line","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/mus_acm.c"},"deprecated":false,"digest":{"line_hashes":["227726273410518958710269584201445417286","277609735454390599593020302753213892440","201925238093322803516874118978487680824","22797891440466018711134145158821279660","207863274498105027805871801169732714857","129667469129503579639724060674026198838","41039891034359540688242295159842704115","12616511260691492847972094834756637813","285702210237374862010406241132795859283","223326511966914072456640840773346854037","128118525530024257850638119121653739636","144892340657499280682089373220899369243"],"threshold":0.9}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}