Sceawere
Vulnerability Detail
CVE-2026-108577UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
libmodplug Resource Consumption Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 4h ago
- Vendor
- Konstanty Bialkowski
- Product
- libmodplug
- Attack Type
- Resource Consumption
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Konstanty Bialkowski libmodplug up to 0.8.9.1. This issue affects the function abc_add_gchord of the file src/load_abc.cpp of the component ABC Music Format Parser. This manipulation causes resource consumption. The attack may be initiated remotely. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T13:17:13.230Z",
"pubdate": "2026-10-11T13:17:13.230Z",
"executiveSummary": "A resource consumption vulnerability has been identified in the Konstanty Bialkowski libmodplug library, specifically within the ABC Music Format Parser component.\nThe vulnerability exists in the abc_add_gchord function within src/load_abc.cpp, affecting all versions up to and including 0.8.9.1.\nThe flaw permits a remote attacker to induce uncontrolled resource consumption, which may lead to a Denial of Service (DoS) condition.\nThe issue stems from insufficient input validation or resource management logic during the processing of maliciously crafted ABC music files.\nGiven that the library is frequently utilized in media processing applications, successful exploitation allows an attacker to degrade or crash the hosting service or application remotely.\nThe vendor has not provided a patch or formal response, leaving implementations vulnerable unless external protective measures are applied.",
"technicalDetails": "The vulnerability is located in the src/load_abc.cpp file of the libmodplug library, specifically within the abc_add_gchord function responsible for parsing ABC music format chord sequences.\nThe root cause of the vulnerability is improper handling of input data provided within the music file, leading to an exhaustion of system resources, likely manifesting as excessive memory allocation or an infinite loop during chord string processing.\nThe attack flow initiates when the libmodplug parser receives a malformed ABC file containing specific chord notation sequences designed to trigger the vulnerable code path in abc_add_gchord.\nWhen the parser reaches the affected function, the application logic fails to properly sanitize or constrain the input length and complexity of the gchord parameters. Consequently, the parser may enter a state where it attempts to allocate disproportionate amounts of memory or performs intensive computational cycles to resolve the malicious input.\nBecause libmodplug is often integrated into media players, browser plugins, or audio processing frameworks, the attack vector is exposed via remote delivery of the malicious file. No authentication or elevated privileges are required to trigger the vulnerability, as the parser processes the untrusted input directly upon ingestion.\nThe resulting resource consumption leads to process instability, where the application may become unresponsive, consume all available system RAM, or hit CPU limits, effectively causing a remote Denial of Service (DoS).\nPost-exploitation, the stability of the host environment is compromised until the offending process is terminated. There is no evidence of arbitrary code execution at this time, though the primary impact remains a complete disruption of service for the target application.\nThis vulnerability highlights a critical lack of input bounds checking in the legacy codebase of libmodplug's music format parsing logic, specifically regarding how chord instructions are interpreted by the library during the load phase."
}