CVE-2026-92880 | vgmstream up to r2117 EA SCHl parser vadpcm_decoder.c vadpcm_read_coefs_be entry/entries out-of-bounds write (Issue 1994)

SecurityVulns

A vulnerability identified as critical has been detected in vgmstream up to r2117. Impacted is the function vadpcm_read_coefs_be of the file src/coding/vadpcm_decoder.c of the component EA SCHl parser. This manipulation of the argument entry/entries causes out-of-bounds write.

This vulnerability is registered as CVE-2026-92880. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to install a patch to address this issue.VulDB Recent EntriesRead More