CVE-2026-105838

Summary

libmikmod before 3.3.14 contains a heap out-of-bounds read vulnerability in the Impulse Tracker loader load_it.c that allows attackers to read adjacent heap memory via oversized patterns. Attackers can supply a crafted IT module with more than 200 pattern rows, causing IT_ConvertTrack() to read past the itpat buffer and crash applications.

Affected Software

VendorProductVersion RangeStatus
sezerolibmikmod0 < 3.3.14affected

Weaknesses

  • CWE-125: Out-of-bounds Read

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References