{"id":"CVE-2026-92881","summary":"vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero","details":"A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be executed remotely. The name of the patch is ae37662ad626254ddd96ad69ac263792d7a92024. A patch should be applied to remediate this issue.","modified":"2026-09-19T08:03:30.222050Z","published":"2026-09-17T15:30:13.793Z","database_specific":{"cwe_ids":["CWE-369","CWE-404"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92881.json","cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/vgmstream/vgmstream/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/92xxx/CVE-2026-92881.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92881"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-92881"},{"type":"ADVISORY","url":"https://vuldb.com/submit/942165"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/406347"},{"type":"REPORT","url":"https://github.com/vgmstream/vgmstream/issues/1996"},{"type":"REPORT","url":"https://vuldb.com/vuln/406347/cti"},{"type":"FIX","url":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024"},{"type":"FIX","url":"https://github.com/vgmstream/vgmstream/pull/2008"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/vgmstream/vgmstream","events":[{"introduced":"0"},{"fixed":"ae37662ad626254ddd96ad69ac263792d7a92024"}],"database_specific":{"source":"REFERENCES"}}],"versions":["r2117","r2083","r2055","r2023","r1980","r1951","r1917","r1896","r1879","r1866","r1843","r1831","r1810","r1800","r1776","r1721","r1702","r1690","r1667","r1640","r1626","r1625","r1050-3448-g77cc431b","r1050-3312-g70d20924","r1050-3280-gba405509","r1050-3264-g86fbfffd","r1050-3258-g0b7c3ce6","r1050-3086-gc9dc860c","r1050-3084-ge114566b","r1050-3072-g39f38e0a","r1050-3022-g877d791d","r1050-2969-g9da8b93f","r1050-2955-g9aaba3b3","r1050-2946-g1e583645","r1050-2908-g14dc8566","r1050-2893-g994ef884","r1050-2874-gcff06e38","r1050-2861-g126e3b41","r1050-2838-g987641d8","r1050-2819-gcec5b596","r1050-2797-g5ea57c08","r1050-2792-gbbeb4e4b","r1050-2780-geea1c3b4","r1050-2771-ge58c73aa","r1050-2743-gc479bdb5","r1050-2359-ge1184142","r1050-2736-g71da1d5e","r1050-2696-g0a04a738","r1050-2651-g2ac2c0ce","r1050-2637-gd871302c","r1050-2625-g02efa7d7","r1050-2579-gcce259d4","r1050-2574-g246222dd","r1050-2553-gee3e1700","r1050-2552-g2b1de051","r1050-2551-g9c8dc69e","r1050-2543-g363b8143","r1050-2539-gc66fe3ee","r1050-2511-g3090c08e","r1050-2501-g15362e0b","r1050-2466-ga349c26b","r1050-2459-ga2fe3aa3","r1050-2441-gd64c3872","r1050-2410-gead9ec4f","r1050-2406-g66626b31","r1050-2395-g056ee4fb","r1050-2384-g1fb124c2","r1050-2366-ged57b41e","r1050-2349-g5fe83c0c","r1050-2345-g1d28e0f5","r1050-2334-g0514807c","r1050-2327-ge003e2c2","r1050-2320-g7bc5b8b1","r1050-2318-g86c104c9","r1050-2307-gc0de147a","r1050-2304-g50309c19","r1050-2297-g3f687f4f","1.0.121","r1050-2287-g9206295e","r1050-2273-g224b4bba","r1050-2259-gcb9b9c0d","r1050-2257-g95e65ea4","r1050-2208-g83b463bf","r1050-2178-gd0de0119","r1050-2142-gd8ffd7f0","r1050-2141-g12ad4237","r1050-2085-gae0f1b61","r1050-2066-g3dc52c5f","r1050-2051-gc9d997f3","r1050-2047-gcfb6b8fe","r1050-2045-gab807c34","r1050-2037-ged397bbc","r1050-2028-gac28ccc5","r1050-2014-g7a8726dd","r1050","r1040","r1039","r1038","r1037","r1036","r1035","r1034","r1033","r1032","r1031","r1030","r1029","r1028","r1027","r1026","r1025","r1024","r1020","r1019","r1018","r1017","r1016","r1015","r1014","r1013","r1012","r1011","r1010","r1009","r1008","r1007","r1004","r1002"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-92881.json","vanir_signatures_modified":"2026-09-19T08:03:30Z","vanir_signatures":[{"source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/coding/vadpcm_decoder.c","function":"vadpcm_read_coefs_be"},"deprecated":false,"digest":{"function_hash":"61950491203349619542819047073684110605","length":424},"id":"CVE-2026-92881-10d99fe5","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/coding/vadpcm_decoder.c"},"deprecated":false,"digest":{"line_hashes":["221741655899341405355520873656546392911","55010596707300793946803163126101891753","250007935213284495856374148068038265277","145199981610081947813644764322382782872","270589024631504215031860228612840538844","190939605965985965651449036493094516727","225260035090917991029688070709497173701","130225355172283258812440062378973838003","257346637233878023777314346350643789729","115724729695296889531713382721604932772"],"threshold":0.9},"id":"CVE-2026-92881-1beb7b82","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/txtp_process.c"},"deprecated":false,"digest":{"line_hashes":["277919035690041846310118315747702608827","191579810583570283803808898342780672284","254811042427858936847494700657405935726","36910391587684210834934834894162261835","70144175419785209738034272747536287741","39795347645260067342377428989831003454","220676604697613284473193676532660606270","189605501174611158398520266823696678613","89048848195360174446663530295313470865","249519714518561596723726149552150668134","142067702656514483413847377251606091935","1766340400062385431205303740956760637","195327080898701314406218649410002094375","324407869122832018574201868759715391835","9804252359644321236787373588718787382","138286893271057811087629221345634609143","109177262425867329259507924992864640238","98149895673777243802297339806656915866","276724982101181025694146884556575863946","218505817112042971847568815641468985994","266299874133884625758235216685082700111","335542039264217065079296989417461294694","296150711073088609084390075015880658975"],"threshold":0.9},"id":"CVE-2026-92881-2b2396ce","signature_type":"Line"},{"digest":{"function_hash":"157031685117792206434395846209534741551","length":2865},"id":"CVE-2026-92881-4b0340c2","signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/mus_acm.c","function":"parse_mus"},"deprecated":false},{"target":{"file":"src/meta/txtp_process.c","function":"make_group_random"},"deprecated":false,"digest":{"function_hash":"197275797228318780486615163501610662271","length":1352},"id":"CVE-2026-92881-52e3c036","signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024"},{"target":{"file":"src/coding/psx_decoder.c","function":"ps_find_padding"},"deprecated":false,"digest":{"length":1471,"function_hash":"292596885354562570734643441974552222465"},"id":"CVE-2026-92881-69150f8f","signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024"},{"id":"CVE-2026-92881-8043c0ea","signature_type":"Line","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/coding/psx_decoder.c"},"deprecated":false,"digest":{"line_hashes":["126366064877753608228551421847227752391","256358577321216918515040422697826661095","324911952815662409498315996761522187675","229062097149129615251734303790004443621","275491718711092959219307275697209147148","716407587958725348062976086138125789","275781060332014179518435619178840708848","226846371991247407173102133515697672838","279706029882529935789883004001216895768"],"threshold":0.9}},{"deprecated":false,"digest":{"function_hash":"65973427816333387397513283991130181863","length":2114},"id":"CVE-2026-92881-872c57cb","signature_type":"Function","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/awb.c","function":"init_vgmstream_awb_memory"}},{"id":"CVE-2026-92881-abe1f893","signature_type":"Line","signature_version":"v1","source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/awb.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["134622419795886457617875045520913668775","214650664164427520112557524052800536473","326437658612950714337511886563505078742","149368706715759937841290787272741104476","154204545848386298322298961008299004146","39882210791512762145354522531301775142","118877436249817330260279694700750649654"]}},{"source":"https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024","target":{"file":"src/meta/mus_acm.c"},"deprecated":false,"digest":{"line_hashes":["227726273410518958710269584201445417286","277609735454390599593020302753213892440","201925238093322803516874118978487680824","22797891440466018711134145158821279660","207863274498105027805871801169732714857","129667469129503579639724060674026198838","41039891034359540688242295159842704115","12616511260691492847972094834756637813","285702210237374862010406241132795859283","223326511966914072456640840773346854037","128118525530024257850638119121653739636","144892340657499280682089373220899369243"],"threshold":0.9},"id":"CVE-2026-92881-e2bec889","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X"}]}