Sceawere
Vulnerability Detail
CVE-2026-105837UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libmikmod DSM Integer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 11h ago
- Vendor
- sezero
- Product
- libmikmod
- Attack Type
- Integer Overflow or Wraparound
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that allows attackers to trigger heap buffer overflow via crafted track counts. Attackers can supply a DSM module whose numchn and numpat product wraps a 16-bit value, overwriting heap memory to cause crashes or potential code execution.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-06T14:17:40.763Z",
"pubdate": "2026-10-06T14:17:40.763Z",
"executiveSummary": "The library libmikmod, prior to version 3.3.14, is susceptible to an integer overflow vulnerability located within the DSM module loading functionality. This flaw occurs in the DSM_Load() function found in load_dsm.c. The vulnerability stems from improper validation of track count parameters within a DSM audio file, specifically the product of numchn and numpat variables.\nAn attacker can exploit this by providing a specially crafted DSM file that induces an integer wrap-around when calculating memory allocation sizes for tracks. This leads to a heap-based buffer overflow, enabling the overwriting of adjacent heap memory. The primary impact of this vulnerability is a denial-of-service via application crash; however, depending on the memory layout and attacker control over the heap, it may facilitate arbitrary code execution.\nThe vulnerability does not require authentication or elevated privileges, provided the user can be induced to process a malicious file. It presents a critical risk to any system or application utilizing libmikmod to parse external audio content, as it allows remote attackers to execute code in the context of the library's host process.",
"technicalDetails": "The vulnerability resides in the DSM_Load() function within the load_dsm.c source file of libmikmod. The flaw is rooted in an integer overflow condition triggered during the computation of memory buffers required to store track information for DSM module files. Specifically, the library performs a calculation based on the product of the number of channels (numchn) and the number of patterns (numpat) defined within the DSM file structure.\nIn the vulnerable code, the logic fails to perform adequate bounds checking or overflow validation before utilizing these variables for heap allocation. When an attacker provides a crafted DSM file where the multiplication of numchn and numpat results in a value exceeding the capacity of a 16-bit integer, the product wraps around to a significantly smaller value. This erroneously low value is then passed to the memory allocation routine (such as malloc or calloc).\nBecause the allocation size is smaller than the amount of data the application subsequently attempts to read from the file into the allocated buffer, a heap-based buffer overflow occurs. During the parsing process, libmikmod proceeds to write track data into the undersized heap chunk, causing an out-of-bounds write that corrupts contiguous memory blocks. This memory corruption can lead to the overwriting of heap metadata, function pointers, or application-specific objects.\nThe attack flow proceeds as follows: 1) The attacker constructs a malicious DSM file with headers designed to trigger the integer wrap-around in the calculation of track-related structures. 2) The victim application invokes libmikmod to parse the malicious file. 3) DSM_Load() processes the corrupted metadata, resulting in an insufficient heap allocation. 4) The library writes the larger-than-allocated track data into the buffer, triggering the heap overflow. 5) The heap corruption is leveraged to cause a program crash (Denial of Service) or, through advanced heap grooming techniques, to redirect control flow to attacker-supplied shellcode or ROP chains, achieving potential remote code execution.\nThis vulnerability affects all versions of libmikmod prior to 3.3.14. It is remotely exploitable without authentication, as the attack vector is file-based processing. The severity is magnified by the fact that many media players and audio processing tools rely on libmikmod as a backend parser, often running with the privileges of the logged-in user."
}