๐Ÿ” CVE Alert

CVE-2026-105837

HIGH 7.8

libmikmod before 3.3.14 Heap Buffer Overflow via DSM Loader Integer Overflow

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
0th

libmikmod before 3.3.14 contains an integer overflow vulnerability in DSM_Load() in load_dsm.c that allows attackers to trigger heap buffer overflow via crafted track counts. Attackers can supply a DSM module whose numchn and numpat product wraps a 16-bit value, overwriting heap memory to cause crashes or potential code execution.

CWE CWE-190
Vendor sezero
Product libmikmod
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for sezero libmikmod

Be the first to know when new high vulnerabilities affecting sezero libmikmod are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

sezero / libmikmod
0 < 3.3.14

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sezero/mikmod/commit/a125eabbd086f311496ae46d08aaebcad0a1c426 github.com: https://github.com/sezero/mikmod/blob/libmikmod-3.3.13/libmikmod/loaders/load_dsm.c#L273 github.com: https://github.com/sezero/mikmod/blob/libmikmod-3.3.14/libmikmod/NEWS github.com: https://github.com/sezero/mikmod vulncheck.com: https://www.vulncheck.com/advisories/libmikmod-before-3.3.14-heap-buffer-overflow-via-dsm-loader-integer-overflow

Credits

Tristan Madani