{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3anothingsstb_vorbis/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nothings:stb_vorbis:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-89266"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["stb_vorbis (\u003c= 1.22)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["nothings"],"content_html":"\u003cp\u003eThe stb_vorbis library, up to and including version 1.22, contains a critical heap-based buffer overflow vulnerability within the start_decoder function. The flaw occurs due to integer truncation when calculating the allocation size for codebook multiplicands; the library incorrectly casts a size_t value to an int, leading to an undersized allocation. An attacker can exploit this vulnerability by providing a specially crafted Ogg Vorbis file containing abnormally large entries and dimensions. Successful exploitation of this vulnerability results in out-of-bounds writes, which can be leveraged to corrupt the heap or achieve arbitrary code execution within the context of the application consuming the audio file. Because stb_vorbis is a common header-only library embedded within various cross-platform applications and game engines, the impact scope is broad, affecting any system parsing untrusted Ogg Vorbis content.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for memory corruption and potential arbitrary code execution. This impacts any software that utilizes the stb_vorbis library to process audio files, including media players, game engines, and transcoding tools on Windows, Linux, and macOS. If the vulnerable application runs with elevated privileges or processes user-provided content from the internet, the risk of exploitation is significantly increased.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all software components within your environment that bundle the stb_vorbis library.\u003c/li\u003e\n\u003cli\u003eUpdate any identified software to a version that utilizes a patched release of stb_vorbis (beyond 1.22).\u003c/li\u003e\n\u003cli\u003eImplement memory safety monitoring for media processing applications to detect heap-related crashes.\u003c/li\u003e\n\u003cli\u003eDisable support for Ogg Vorbis files in applications where it is not required for core functionality to reduce the attack surface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-12T01:16:26Z","date_published":"2026-09-12T01:16:26Z","id":"https://feed.craftedsignal.io/briefs/2026-09-stb-vorbis-heap-overflow/","summary":"A heap-based buffer overflow in the stb_vorbis library allows for arbitrary code execution via a maliciously crafted Ogg Vorbis audio file.","title":"Heap Buffer Overflow in stb_vorbis","url":"https://feed.craftedsignal.io/briefs/2026-09-stb-vorbis-heap-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:nothings:stb_vorbis:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}