libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT module whose SLEN chunk wraps the 16-bit numtrk value, causing PBOD writes past allocated track pointers for crashes or code execution.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 Oct 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | libmikmod before 3.3.14 contains an integer overflow in the Oktalyzer loader OKT_doPBOD() that allows attackers to cause heap buffer overflow via crafted track counts. Attackers can supply an OKT module whose SLEN chunk wraps the 16-bit numtrk value, causing PBOD writes past allocated track pointers for crashes or code execution. | |
| Title | libmikmod before 3.3.14 Heap Buffer Overflow via OKT Loader OKT_doPBOD | |
| First Time appeared |
Raphael Assenat
Raphael Assenat libmikmod |
|
| Weaknesses | CWE-190 | |
| CPEs | cpe:2.3:a:raphael_assenat:libmikmod:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Raphael Assenat
Raphael Assenat libmikmod |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-06T13:35:45.261Z
Reserved: 2026-10-05T22:00:10.842Z
Link: CVE-2026-105839
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses