OESA-2026-3604

    Dashboard / Vulnerabilities / OESA-2026-3604

    OESA-2026-3604

    Published: 5 Sept 2026Last Modified: 5 Sept 2026
    Upstream:

    Summary: libmodplug security update

    Details: The library which was part of the Modplug-xmms project. Security Fix(es): libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state.(CVE-2026-75904)

    Affected packages

    Package

    Name: libmodplug

    Purl: pkg:rpm/openEuler/libmodplug&distro=openEuler-22.03-LTS-SP4

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -0.8.9.0-11.oe2203sp4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    OESA-2026-3604 | CVE-DB