Resource Consumption Vulnerability in vgmstream Product by Developer
CVE-2026-92879

5.3MEDIUM

Key Information:

Vendor

vgmstream

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92879?

A security flaw has been identified in vgmstream versions up to r2117, specifically affecting the parse_mus function within the src/meta/mus_acm.c file. This vulnerability allows for resource consumption manipulation, potentially leading to service disruptions. The issue can be exploited remotely, making it critical for users to apply the recommended patch (ae37662ad626254ddd96ad69ac263792d7a92024) to mitigate risks associated with this vulnerability.

Affected Version(s)

vgmstream r2117

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ni-liao (VulDB User)
.