CVE-2026-105839: libmikmod before 3.3.14 Heap Buffer Overflow via OKT Loader OKT_doPBOD
libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKTdoPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT module whose SLEN chunk wraps the 16-bit numtrk value, causing PBOD writes past allocated track pointers for crashes or code execution.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
They must cause libmikmod to process a crafted OKT module. The module's SLEN chunk uses track counts that wrap the 16-bit numtrk value, leading to writes beyond the allocated track-pointer array during PBOD processing.
Are applications that merely have libmikmod installed exposed?
Exploitation requires the application to load an attacker-controlled OKT module through libmikmod. The provided data does not establish exposure without processing such untrusted module content.
What should be done if an update cannot be applied immediately?
Avoid loading untrusted or externally supplied OKT modules with affected libmikmod versions. Restrict module inputs to trusted sources until libmikmod can be updated to 3.3.14 or later.
How can I determine whether my deployment is affected?
Check the installed libmikmod version and whether the application processes OKT modules. Versions before 3.3.14 are affected when they load a crafted OKT module.