PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92880 vgmstream CVE debrief

A weakness was identified in vgmstream up to r2117, specifically in the vadpcm_read_coefs_be function of the src/coding/vadpcm_decoder.c file, which is part of the EA SCHl parser. This weakness leads to an out-of-bounds write vulnerability when manipulating the argument entry/entries. The vulnerability can be exploited remotely. A patch (ae37662ad626254ddd96ad69ac263792d7a92024) has been suggested to address this issue.

Vendor
vgmstream
Product
vgmstream
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-17
Original CVE updated
2026-09-22
Advisory published
2026-09-17
Advisory updated
2026-09-22

Who should care

Defenders responsible for systems using vgmstream up to r2117 should assess exposure and apply the patch (ae37662ad626254ddd96ad69ac263792d7a92024) to mitigate the vulnerability. This includes operators, platform administrators, and security teams who need to review and update inventory of affected systems, perform vulnerability scanning, and implement compensating controls for exposed systems.

Why it matters

CVE-2026-92880 is an out-of-bounds write vulnerability in vgmstream up to r2117, which can be exploited remotely. Defenders should assess exposure, apply the patch, and monitor for potential exploitation attempts.

  • Remote exploitation of the vulnerability is possible.
  • The vulnerability can lead to an out-of-bounds write, potentially causing system instability or crashes.
  • Defenders should verify if the patch has been applied to prevent potential exploitation.
  • The vulnerability has a medium CVSS score of 5.3, indicating a moderate level of risk.

Technical summary

The vadpcm_read_coefs_be function in src/coding/vadpcm_decoder.c of vgmstream up to r2117 is vulnerable to an out-of-bounds write attack when manipulating the argument entry/entries. This weakness can be exploited remotely, potentially causing system instability or crashes. Defenders should assess exposure, apply the patch (ae37662ad626254ddd96ad69ac263792d7a92024), and monitor for potential exploitation attempts to mitigate the vulnerability. The vulnerability has a medium CVSS score of 5.3, indicating a moderate level of risk.

Defensive priority

Medium priority given the CVSS score of 5.3 and the availability of a patch.

Recommended defensive actions

  • Assess exposure by checking if the vulnerable version of vgmstream (up to r2117) is in use.
  • Verify if the patch (ae37662ad626254ddd96ad69ac263792d7a92024) has been applied.
  • Monitor for potential exploitation attempts.
  • Review and update inventory of affected systems.
  • Perform vulnerability scanning to identify instances of vgmstream up to r2117.
  • Implement compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, including its description, CVSS score, and affected versions. However, the vendor and product names are not specified, and the CVE record does not provide additional information on exploitation or impact.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92880 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92880

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92880 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92880

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.