NIXPKGS-2026-2652
GitHub issue
published 10 hours ago
vgmstream mus_acm.c parse_mus resource consumption
Permalink
CVE-2026-92879
5.3 MEDIUM
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): Passive (P)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): Not Defined (X)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Passive (P)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package deadbeefPlugins.vgmstream
- @LeSuisse ignored reference https://g…
- @LeSuisse accepted
- @LeSuisse published on GitHub
vgmstream mus_acm.c parse_mus resource consumption
A security flaw has been discovered in vgmstream up to r2117. This issue affects the function parse_mus of the file src/meta/mus_acm.c. The manipulation results in resource consumption. The attack may be launched remotely. The patch is identified as ae37662ad626254ddd96ad69ac263792d7a92024. Applying a patch is advised to resolve this issue.
References
-
-
-
CVE-2026-92879 | CVE Analysis and Report third-party-advisory
-
Submit #942160 | vgmstream r2117 Resource Consumption third-party-advisory
-
https://github.com/vgmstream/vgmstream/issues/1993 issue-tracking
-
Ignored references (1)
Affected products
vgmstream
- ==r2117
Matching in nixpkgs
Ignored packages (1)
pkgs.deadbeefPlugins.vgmstream
Streaming video game music decoder plugin for the DeaDBeeF music player
-
nixos-unstable 2026-06-22
- nixpkgs-unstable 2026-06-22
- nixos-unstable-small 2026-06-22
-
nixos-26.05 2026-05-09.1
- nixos-26.05-small 2026-05-09.1
- nixpkgs-26.05-darwin 2026-05-09.1
Package maintainers
-
@vs49688 Zane van Iperen <zane@zanevaniperen.com>