Sceawere

Vulnerability Detail

CVE-2026-105839UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

libmikmod Integer Overflow Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
11h ago
Vendor
sezero
Product
libmikmod
Attack Type
Integer Overflow or Wraparound
Vector String
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT module whose SLEN chunk wraps the 16-bit numtrk value, causing PBOD writes past allocated track pointers for crashes or code execution.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-06T14:17:41.133Z",
  "pubdate": "2026-10-06T14:17:41.133Z",
  "executiveSummary": "An integer overflow vulnerability exists in the Oktalyzer loader of libmikmod versions prior to 3.3.14. This vulnerability is triggered when processing the OKT file format, specifically within the OKT_doPBOD() function. By supplying a specially crafted OKT module containing manipulated SLEN chunk data, an attacker can induce an integer overflow related to the 16-bit numtrk value. This overflow leads to an insufficient allocation of memory, subsequently resulting in a heap-based buffer overflow during the processing of track data. The vulnerability poses a significant risk to applications utilizing libmikmod to parse untrusted audio files, as successful exploitation may result in an application crash (Denial of Service) or arbitrary code execution within the context of the user running the affected software. Exploitation does not require prior authentication but necessitates that the victim process a maliciously crafted OKT file. The lack of proper boundary checks during the translation of the SLEN chunk to track pointers serves as the primary vector for this memory corruption.",
  "technicalDetails": "The vulnerability resides within the OKT_doPBOD() function of the libmikmod Oktalyzer module loader. The root cause is an integer overflow occurring during the calculation of track pointers based on metadata embedded within the file structure. Specifically, the loader processes the SLEN chunk of an OKT file, which influences the numtrk (number of tracks) value, defined as a 16-bit unsigned integer.\nDuring the parsing of the OKT module, the application reads the SLEN chunk to determine how much memory to allocate for track-related data. Due to the lack of adequate input validation on the length fields provided in the file, an attacker can craft an SLEN chunk that forces an overflow when the 16-bit numtrk value is processed or used in subsequent memory size calculations. This integer overflow causes the underlying allocator to reserve a heap buffer that is smaller than the actual amount of data being processed by the OKT_doPBOD() function.\nThe attack flow proceeds as follows: 1) An attacker prepares a malicious OKT file with a deliberately manipulated SLEN chunk designed to trigger the overflow condition. 2) The victim application utilizes libmikmod to load and parse this malicious file. 3) Upon reaching the OKT_doPBOD() routine, the application interprets the forged metadata, resulting in the insufficient heap allocation. 4) The function attempts to perform writes of PBOD track data into the inadequately sized heap buffer. 5) These write operations extend past the allocated boundary, corrupting adjacent heap memory structures. 6) The memory corruption can be leveraged by the attacker to overwrite sensitive pointers or control data, potentially leading to arbitrary code execution or, at minimum, a crash resulting in a Denial of Service. The vulnerability affects libmikmod versions earlier than 3.3.14, specifically those that implement the legacy Oktalyzer support without sufficient boundary checks on track count arithmetic."
}
CVE-2026-105839: libmikmod Integer Overflow Vulnerability (HIGH Severity, CVSS: 7.8) | Sceawere