CVE-2026-105250: vgmstream Microsoft IMA Decoder ima_decoder.c decode_ms_ima divide by zero
Published Oct 5, 2026
·Updated
A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decodemsima of the file src/coding/imadecoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely.
Affected Software
1 affected component
vgmstream vgmstream<=r2117
Event History
Oct 5, 2026
CVE Published
via MITRE·07:45 AM
Data Sourced
via MITRE·07:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What attacker interaction is required for exploitation?
The vector is network-accessible and requires user interaction. No privileges are required.
2
What security impact is reported?
The reported impact is limited to availability. Confidentiality and integrity are not affected in the supplied scoring data.
3
Which releases are known to be affected?
vgmstream versions up to r2117 are identified as affected. The provided information does not identify a fixed release or workaround.