CVE-2026-92881: vgmstream AWB parser awb.c init_vgmstream_awb_memory divide by zero
A security vulnerability has been detected in vgmstream. The affected element is the function initvgmstreamawbmemory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be executed remotely. The name of the patch is ae37662ad626254ddd96ad69ac263792d7a92024. A patch should be applied to remediate this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vgmstream/AWB parser (src/meta/awb.c) - init_vgmstream_awb_memoryto a version that resolves this vulnerability.Patch ae37662ad626254ddd96ad69ac263792d7a92024
Event History
Frequently Asked Questions
What would an attacker need to do to trigger this issue?
The attacker would need to cause vgmstream to process a manipulated AWB file. Exploitation requires user interaction, despite being remotely executable.
What is the impact of successful exploitation?
The reported impact is availability only: the divide-by-zero condition may cause a denial of service. No confidentiality or integrity impact is indicated.
How can this be remediated?
Apply the patch identified as ae37662ad626254ddd96ad69ac263792d7a92024. The provided data does not identify affected or fixed release versions.