{"id":"GHSA-8j4c-6x6g-rq3j","summary":"music-metadata: uncatchable process crash parsing a crafted `.dsf` (residual of GHSA-v6c2-xwv6-8xf7)","details":"## Summary\n`DsfParser.parseChunks` skips an unrecognised chunk's payload with an **un-awaited** call:\n```js\nthis.tokenizer.ignore(Number(chunkHeader.size) - ChunkHeader.len);   // lib/dsf/DsfParser.js:51 — no await\n```\n`ChunkHeader.len` is 12. A crafted `.dsf` chunk with `id != 'fmt '` and `size` in `0..11` makes the\nargument negative; strtok3 (≥ 10.3.5) throws `RangeError` on a negative `ignore`. Because the call\nis fire-and-forget, the rejection is **detached from the `parseBuffer()` promise chain** → unhandled\nrejection → Node's default (≥ 15) **crashes the process** — **after** `parseBuffer()` already\nresolved, so a caller's `try/catch` catches nothing and is still taken down.\n\nResidual of GHSA-v6c2-xwv6-8xf7: the ASF site was fixed in 11.12.3 (size validation) and strtok3\nnow throws on negative `ignore`; the DSF site was never validated, and its missing `await`\nescalates that throw into an **uncatchable** crash.\n\n## Root cause (`lib/dsf/DsfParser.js:34-56`)\n```js\nwhile (bytesRemaining \u003e= ChunkHeader.len) {               // ChunkHeader.len = 12\n  const chunkHeader = await this.tokenizer.readToken(ChunkHeader);   // { id, size }\n  switch (chunkHeader.id) {\n    case 'fmt ': { ...; return; }\n    default: this.tokenizer.ignore(Number(chunkHeader.size) - ChunkHeader.len); break;  // size\u003c12 -\u003e negative, no await\n  }\n  bytesRemaining -= chunkHeader.size;\n}\n```\nstrtok3 `AbstractTokenizer.ignore` (L78-79): `if (length \u003c 0) throw new RangeError('ignore length must be ≥ 0 bytes');`\n\n## Steps to reproduce\n`repro/` — public API only, Node's default unhandled-rejection mode, `try/catch` around the parse:\n```\nnpm install && node poc.mjs\n```\nConfirmed on 11.14.0:\n```\n[app] parseBuffer() RESOLVED — the caller saw no error to catch.\nRangeError: ignore length must be ≥ 0 bytes\n    at DsfParser.parseChunks (.../lib/dsf/DsfParser.js:51)\n   \u003cprocess exits non-zero — the \"process survived\" line never prints\u003e\n```\n\n## Impact\nDoS: a single crafted `.dsf` (or any file with the `DSD ` magic) crashes the Node process of any\napp parsing untrusted audio with music-metadata (2.2M weekly downloads). The crash bypasses the\ncaller's error handling, so even apps that correctly `try/catch` per-file parsing are killed — one\nmalicious upload can take down a shared server/worker.\n\n## Remediation\nAdd `await` on line 51 (makes the `RangeError` a catchable parse error), and validate\n`chunkHeader.size \u003e= ChunkHeader.len` before the skip (as the ASF fix did; also guards the loop\ncounter). Audit other parsers for un-awaited `tokenizer.ignore()`/`readToken()`.\n\n## Scope / honesty\nRequires the DSF path (a `DSD `-magic file — normal auto-detection). Relies on Node's default\nunhandled-rejection mode (`throw`, default since Node 15); the point is that the standard defensive\nper-parse `try/catch` does not protect against it. Crash (availability), not disclosure/RCE.\nNegatives confirmed alongside: ASF infinite loop fixed; negative-`ignore` infinite-loop class\nclosed at strtok3; unbounded allocation bounded by strtok3's read bound-check.\n\n## Credits\nIssue also reported by @ryu7eroo","aliases":["CVE-2026-107392"],"modified":"2026-10-08T20:00:05.860263177Z","published":"2026-10-08T19:40:45Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-10-08T19:40:45Z","nvd_published_at":null,"cwe_ids":["CWE-248","CWE-400"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/Borewit/music-metadata/security/advisories/GHSA-8j4c-6x6g-rq3j"},{"type":"WEB","url":"https://github.com/Borewit/music-metadata/pull/2700"},{"type":"WEB","url":"https://github.com/Borewit/music-metadata/commit/e7fc27a96e789d41ece41fdac590fc7618274a41"},{"type":"PACKAGE","url":"https://github.com/Borewit/music-metadata"},{"type":"WEB","url":"https://github.com/Borewit/music-metadata/releases/tag/v11.15.0"}],"affected":[{"package":{"name":"music-metadata","ecosystem":"npm","purl":"pkg:npm/music-metadata"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"11.15.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 11.14.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-8j4c-6x6g-rq3j/GHSA-8j4c-6x6g-rq3j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}