{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/libmikmod--3.3.14/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:libmikmod:libmikmod:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-105837"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libmikmod (\u003c 3.3.14)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","buffer-overflow"],"_cs_type":"advisory","_cs_vendors":["libmikmod"],"content_html":"\u003cp\u003elibmikmod, a portable sound library, contains an integer overflow vulnerability in the DSM_Load function located in load_dsm.c. This flaw affects all versions of the library prior to 3.3.14. The issue arises when the library parses a crafted DSM audio module file containing specific track count values. Specifically, the multiplication of the 'numchn' and 'numpat' parameters causes a 16-bit integer overflow. This overflow leads to an undersized allocation on the heap, which subsequently triggers a heap-based buffer overflow during memory write operations. An attacker who successfully delivers a malicious DSM file to an application utilizing the affected libmikmod version can cause a segmentation fault (application crash) or achieve arbitrary code execution within the context of the host process. This vulnerability is significant for any media player, game, or utility that processes untrusted music module files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the compromise of applications relying on libmikmod for audio decoding. Depending on the privileges of the target application, this could result in service disruption (denial of service via crash) or remote code execution. Given the prevalence of libmikmod in legacy gaming engines and multimedia software, the potential scope includes desktop users and server-side applications that perform media transcoding or file analysis.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of libmikmod to version 3.3.14 or later to address the integer overflow in DSM_Load.\u003c/li\u003e\n\u003cli\u003eImplement memory safety tools such as AddressSanitizer (ASAN) during the build process of applications linking against libmikmod to detect heap corruption attempts in test environments.\u003c/li\u003e\n\u003cli\u003eRestrict the processing of untrusted DSM module files to sandboxed processes with minimal system privileges to contain potential code execution.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T14:56:03Z","date_published":"2026-10-06T14:55:56Z","id":"https://feed.craftedsignal.io/briefs/2026-10-libmikmod-integer-overflow/","summary":"An integer overflow in libmikmod versions prior to 3.3.14 allows remote attackers to trigger heap buffer overflows via crafted DSM module files, potentially resulting in code execution.","title":"Integer Overflow Vulnerability in libmikmod DSM_Load","url":"https://feed.craftedsignal.io/briefs/2026-10-libmikmod-integer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - Libmikmod (\u003c 3.3.14)","version":"https://jsonfeed.org/version/1.1"}