<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:libmikmod:libmikmod:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3alibmikmodlibmikmod/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 14:55:56 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3alibmikmodlibmikmod/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Integer Overflow Vulnerability in libmikmod DSM_Load</title><link>https://feed.craftedsignal.io/briefs/2026-10-libmikmod-integer-overflow/</link><pubDate>Tue, 06 Oct 2026 14:55:56 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-libmikmod-integer-overflow/</guid><description>An integer overflow in libmikmod versions prior to 3.3.14 allows remote attackers to trigger heap buffer overflows via crafted DSM module files, potentially resulting in code execution.</description><content:encoded><![CDATA[<p>libmikmod, a portable sound library, contains an integer overflow vulnerability in the DSM_Load function located in load_dsm.c. This flaw affects all versions of the library prior to 3.3.14. The issue arises when the library parses a crafted DSM audio module file containing specific track count values. Specifically, the multiplication of the 'numchn' and 'numpat' parameters causes a 16-bit integer overflow. This overflow leads to an undersized allocation on the heap, which subsequently triggers a heap-based buffer overflow during memory write operations. An attacker who successfully delivers a malicious DSM file to an application utilizing the affected libmikmod version can cause a segmentation fault (application crash) or achieve arbitrary code execution within the context of the host process. This vulnerability is significant for any media player, game, or utility that processes untrusted music module files.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for the compromise of applications relying on libmikmod for audio decoding. Depending on the privileges of the target application, this could result in service disruption (denial of service via crash) or remote code execution. Given the prevalence of libmikmod in legacy gaming engines and multimedia software, the potential scope includes desktop users and server-side applications that perform media transcoding or file analysis.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all instances of libmikmod to version 3.3.14 or later to address the integer overflow in DSM_Load.</li>
<li>Implement memory safety tools such as AddressSanitizer (ASAN) during the build process of applications linking against libmikmod to detect heap corruption attempts in test environments.</li>
<li>Restrict the processing of untrusted DSM module files to sandboxed processes with minimal system privileges to contain potential code execution.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>buffer-overflow</category></item></channel></rss>