Heap Buffer Overflow in libmikmod Affects Multiple Audio Applications
CVE-2026-105837

8.5HIGH

Key Information:

Vendor

Sezero

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105837?

The libmikmod library prior to version 3.3.14 is susceptible to an integer overflow vulnerability located in the DSM_Load() function. This issue arises due to improper handling of track counts in a DSM module, allowing attackers to craft malicious inputs that can cause the numchn and numpat multiplication to exceed the bounds of a 16-bit integer. As a result, this can lead to a heap buffer overflow, permitting attackers to overwrite critical memory areas, potentially leading to application crashes or unauthorized code execution.

Affected Version(s)

libmikmod 0 < 3.3.14

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.