Bug 2543784

Summary: CVE-2026-102804 stb: stb: Denial of Service via integer overflow in hexwave_init [fedora-all]
Product: [Fedora] Fedora Reporter: Ganesh <gnaik>
Component: stbAssignee: Ben Beasley <code>
Status: CLOSED WONTFIX QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: rawhideCC: code, mhroncok
Target Milestone: ---Keywords: Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["7f5e275c-f912-4caf-b8c6-dd42061f6aa7"]}
Fixed In Version: Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2026-09-30 07:04:53 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2543759    

Description Ganesh 2026-09-30 03:21:50 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Comment 1 Ben Beasley 2026-09-30 07:04:53 UTC
(In reply to Ganesh from comment #0)
> Remote exploitation of the attack is possible.

This is just silly. The only way this could be exploited remotely is if someone decides to build a system that takes the initial parameters for this audio oscillator written in C from the network. Sure, that’s possible, but by that logic, every bug that can be triggered by passing a C function bad parameters is remotely exploitable, and so is my washing machine, because it’s possible for me to take it apart and connect a network-controlled servomotor to the temperature dial, and if I did that someone could maliciously shrink my underwear.

I don’t expect upstream to pay attention to this report, and if they do, I expect they will close it without comment or investigation due to the use of AI.

To be sure, it’s better for routines like this to perform parameter validation up front and not to explode when ill-documented limits are exceeded. I’m tracking the upstream issue, and I’ll be happy to apply a sane patch downstream if one appears. I’m still going to close this as WONTFIX because I’m not personally planning to work on a patch, and I doubt anyone else is going to bother either.