CVE-2026-105837: high-severity vulnerability in sezero libmikmod
libmikmod before 3.3.14 Heap Buffer Overflow via DSM Loader Integer Overflow
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.5epss 0.1%
exploitation probability
0.1%top 96% of all CVEs
observed exploitation
nono source reports it
libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that allows attackers to trigger heap buffer overflow via crafted track counts. Attackers can supply a DSM module whose numchn and numpat product wraps a 16-bit value, overwriting heap memory to cause crashes or potential code execution.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
sezero · libmikmodRelated CVEs — sezero libmikmod
In the same product, most dangerous first.
References
https://github.com/sezero/mikmodhttps://github.com/sezero/mikmod/blob/libmikmod-3.3.13/libmikmod/loaders/load_dsm.c#L273https://github.com/sezero/mikmod/blob/libmikmod-3.3.14/libmikmod/NEWShttps://github.com/sezero/mikmod/commit/a125eabbd086f311496ae46d08aaebcad0a1c426https://www.vulncheck.com/advisories/libmikmod-before-3.3.14-heap-buffer-overflow-via-dsm-loader-integer-overflow