PatchSiren

nothings CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH nothings CVE published 2026-09-12

CVE-2026-89266

A heap buffer overflow vulnerability exists in stb_vorbis through 1.22, where the codebook multiplicands allocation size is truncated from size_t to int in the start_decoder() function. This can be exploited by crafting a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.

MEDIUM nothings CVE published 2026-09-09

CVE-2026-79516

CVE-2026-79516 is a Denial of Service (DoS) vulnerability in the stbsp_vsnprintf function of nothings stb commit 31c1ad3. The vulnerability allows attackers to cause a DoS via sending a crafted input. The CVSS score is 4, and the severity is MEDIUM. This vulnerability affects product deployments using nothings stb commit 31c1ad3. Defenders and developers should verify the affected versions and apply patch [truncated]

MEDIUM Nothings CVE published 2025-04-08

CVE-2025-3408

A critical integer overflow vulnerability exists in the stb_dupreplace function of Nothings stb image library, affecting versions up to commit f056911. The vulnerability can be triggered remotely through manipulation of the affected function, potentially leading to memory corruption or other undefined behavior. The stb library uses continuous delivery with rolling releases, meaning no traditional version [truncated]

MEDIUM Nothings CVE published 2025-04-08

CVE-2025-3407

A vulnerability in Nothings stb image library, specifically in the `stbhw_build_tileset_from_image` function, allows out-of-bounds read through manipulation of the `h_count` and `v_count` arguments. The vulnerability is remotely exploitable and affects versions up to commit f056911. The vendor uses a rolling release model and did not respond to disclosure attempts. The vulnerability was published on April [truncated]

MEDIUM Nothings CVE published 2025-04-08

CVE-2025-3406

A vulnerability in Nothings stb image library, specifically in the stbhw_build_tileset_from_image function of the Header Array Handler component, allows out-of-bounds read through manipulation of the width argument. The issue affects stb_image.h up to version 2.13 and can be exploited remotely. The vendor uses a rolling release model and did not respond to disclosure attempts.