Heap Out-of-Bounds Read in libmikmod Affects Multiple Applications
CVE-2026-105838

6.8MEDIUM

Key Information:

Vendor

Sezero

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-105838?

The libmikmod library before version 3.3.14 is susceptible to a heap out-of-bounds read vulnerability within the Impulse Tracker loader. This flaw permits attackers to exploit crafted IT modules containing excessive pattern rows, leading to adjacent heap memory being read. Specifically, when the IT_ConvertTrack() function processes modules with over 200 pattern rows, it inadvertently accesses memory outside the bounds of the intended buffer, potentially causing application crashes and unauthorized data access.

Affected Version(s)

libmikmod 0 < 3.3.14

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tristan Madani
.