Sceawere
Vulnerability Detail
CVE-2026-105838UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libmikmod Heap Out-of-Bounds Read
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.5
- Creation Date
- 11h ago
- Vendor
- sezero
- Product
- libmikmod
- Attack Type
- Out-of-bounds Read
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
libmikmod before 3.3.14 contains a heap out-of-bounds read vulnerability in the Impulse Tracker loader load_it.c that allows attackers to read adjacent heap memory via oversized patterns. Attackers can supply a crafted IT module with more than 200 pattern rows, causing IT_ConvertTrack() to read past the itpat buffer and crash applications.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.5",
"pubDate": "2026-10-06T14:17:40.953Z",
"pubdate": "2026-10-06T14:17:40.953Z",
"executiveSummary": "A heap-based out-of-bounds read vulnerability exists in libmikmod versions prior to 3.3.14 within the Impulse Tracker (IT) module loader.\nThe vulnerability resides in the load_it.c source file, specifically triggered when the application processes malformed IT module files containing an excessive number of pattern rows.\nAn attacker can exploit this flaw by providing a specially crafted audio file. When parsed by the library, the application performs an out-of-bounds memory access beyond the allocated itpat buffer.\nThe primary impact of this vulnerability is an application crash, resulting in a denial-of-service (DoS) condition. Furthermore, the ability to read adjacent heap memory may theoretically facilitate sensitive information disclosure, depending on the memory layout and the specific data residing in the proximity of the buffer.\nThis vulnerability does not require authentication or elevated privileges, as it is triggered during the processing of untrusted input files by the affected library.",
"technicalDetails": "The vulnerability is situated within the Impulse Tracker module loader of libmikmod, specifically in the load_it.c file. The root cause is a lack of proper boundary validation when processing IT module patterns in the IT_ConvertTrack() function.\nThe IT file format allows for pattern data structures; however, libmikmod fails to enforce strict limits on the number of pattern rows. When an attacker supplies a crafted IT file specifying more than 200 pattern rows, the internal tracking logic miscalculates the required buffer size or index offset for the itpat buffer.\nDuring the execution of IT_ConvertTrack(), the function attempts to access the itpat buffer at an offset derived from the excessive row count. Because the buffer was allocated based on expected constraints, the index access falls outside the allocated heap memory boundary.\nThe attack flow proceeds as follows: 1) An attacker creates a malicious IT module file incorporating a pattern header that declares an invalid or oversized row count (specifically > 200). 2) The target application, utilizing an affected version of libmikmod, attempts to load and play this module. 3) The library's loader function triggers the vulnerable code path in load_it.c. 4) The application reads memory locations adjacent to the itpat buffer, leading to a memory access violation (SIGSEGV) and an immediate crash.\nThe vulnerability affects libmikmod versions before 3.3.14. Since libmikmod is frequently used as a background audio processing library in various media players and applications, any software linked to this version of the library is susceptible to this attack vector. Exploitation occurs entirely in the context of the memory space owned by the process loading the malicious file. While the primary documented outcome is a denial-of-service due to an application crash, the out-of-bounds read inherently exposes the contents of neighboring heap segments, which could contain pointers, sensitive user data, or other metadata, depending on the state of the heap at the time of the illegal read. No authentication is required for this exploitation, as the vulnerability is triggered by the standard file-parsing logic employed by the library when handling user-provided input."
}