Vgmstream Security Flaw in AWB Parser Affecting Remote Execution
CVE-2026-92881

5.3MEDIUM

Key Information:

Vendor

vgmstream

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-92881?

A divide by zero vulnerability has been identified in the AWB parser of vgmstream, specifically within the init_vgmstream_awb_memory function located in src/meta/awb.c. This vulnerability could allow an attacker to execute code remotely. To mitigate this risk, a patch with commit ID ae37662ad626254ddd96ad69ac263792d7a92024 has been released and should be applied promptly.

Affected Version(s)

vgmstream

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ni-liao (VulDB User)
.