Bug 2521959 - CVE-2026-75904 libmodplug: libmodplug: Out-of-bounds read via crafted MIDI file [fedora-all]
Summary: CVE-2026-75904 libmodplug: libmodplug: Out-of-bounds read via crafted MIDI fi...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: libmodplug
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Antonio T. sagitter
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["22a48cc2-ca85-4205-832c-3...
Depends On:
Blocks: CVE-2026-75904
TreeView+ depends on / blocked
 
Reported: 2026-08-24 14:08 UTC by Vladimir Vasilev
Modified: 2026-08-24 14:08 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Vladimir Vasilev 2026-08-24 14:08:04 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplooped in src/load_pat.cpp. The function validates only the upper bound of its sample index against MAXSMP and then subtracts one before indexing the 191-byte static array pat_loops, so an index of zero reads pat_loops[-1], one byte before the array. The index is the smpno field of a parsed MIDI event, which is initialised to zero and only later overwritten from a program-change parameter, so an event reaching the note test before an instrument is assigned carries zero. A 32-byte MIDI file supplied to the library's public ModPlug_Load entry point drives the path through CSoundFile::Create, CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read out of bounds determines whether a note event is treated as looping, so adjacent static storage influences playback state.


Note You need to log in before you can comment on or make changes to this bug.