Sceawere
Vulnerability Detail
CVE-2026-105250UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Microsoft IMA Decoder Divide-by-Zero
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 11h ago
- Vendor
- n/a
- Product
- vgmstream
- Attack Type
- Divide By Zero
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-05T08:17:15.610Z",
"pubdate": "2026-10-05T08:17:15.610Z",
"executiveSummary": "A divide-by-zero vulnerability exists in vgmstream up to r2117 within the Microsoft IMA Decoder component. The flaw is located in the decode_ms_ima function within src/coding/ima_decoder.c. This vulnerability allows a remote attacker to trigger a crash, potentially leading to a denial-of-service condition.\nThe vulnerability occurs due to improper input validation when processing malformed audio data, specifically when the codec encounters parameters that result in a division operation by an uninitialized or zero-valued divisor. Successful exploitation requires the application to process a specially crafted malicious audio file. There are no authentication requirements for an attacker to target the decoder, and the vulnerability can be exploited remotely by delivering the malicious payload to a system utilizing the affected vgmstream version.\nThe primary risk implication is system instability and service disruption, as the resulting exception typically forces the termination of the host process. Users of vgmstream are advised to restrict processing of untrusted audio files and ensure that the library is isolated within a sandboxed environment where possible.",
"technicalDetails": "The vulnerability resides in the src/coding/ima_decoder.c file of the vgmstream library, specifically within the decode_ms_ima function responsible for processing Microsoft IMA ADPCM audio streams. The root cause is an insufficient validation of codec-specific parameters extracted from the audio container format before performing arithmetic operations.\nIn the context of the IMA ADPCM decoding algorithm, the decoder relies on specific header fields to determine internal state variables, such as step size or predictor values. If an attacker provides a malformed file containing header fields that manipulate these internal variables to zero, the subsequent decoding loop attempts a division operation using these tainted values. Since the code does not perform an explicit check to verify that the divisor is non-zero before the instruction is executed, the CPU generates a floating-point or integer division exception (SIGFPE on POSIX systems), causing the application to crash.\nThe attack flow proceeds as follows: An attacker creates a malicious audio file where the metadata or IMA ADPCM stream headers are crafted to set the divisor variable to zero during the state initialization phase of the decode_ms_ima function. When the target application invokes vgmstream to parse or play this file, the library parses the malicious headers and stores the zero value in the corresponding internal state structure. As the decoding loop progresses to the point of processing audio blocks, the function triggers a division operation. The lack of an input sanitization routine allows this zero value to reach the divisor register, resulting in a hardware-level divide-by-zero exception.\nBecause the function processes data directly from the input stream, the exploitation is deterministic. If the library is integrated into a network service or a media player that automatically processes remote files, an attacker can trigger the crash remotely without requiring prior authentication or user interaction beyond the file delivery. The post-exploitation impact is limited to a denial-of-service (DoS) as the exception typically leads to an unhandled signal, resulting in the immediate termination of the vgmstream-based process. There is no evidence currently indicating that this primitive can be escalated to arbitrary code execution, though it effectively renders the affected component unusable when processing the malicious input."
}