Bug 2543784 - CVE-2026-102804 stb: stb: Denial of Service via integer overflow in hexwave_init [fedora-all]
Summary: CVE-2026-102804 stb: stb: Denial of Service via integer overflow in hexwave_i...
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: stb
Version: rawhide
Hardware: Unspecified
OS: Unspecified
medium
medium
Target Milestone: ---
Assignee: Ben Beasley
QA Contact:
URL:
Whiteboard: {"flaws": ["7f5e275c-f912-4caf-b8c6-d...
Depends On:
Blocks: CVE-2026-102804
TreeView+ depends on / blocked
 
Reported: 2026-09-30 03:21 UTC by Ganesh
Modified: 2026-09-30 07:04 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-09-30 07:04:53 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Github nothings stb issues 1961 0 None open [SECURITY] Integer overflow in hexwave_init() causes heap/stack buffer overflow in stb_hexwave.h 2026-09-30 07:04:52 UTC

Description Ganesh 2026-09-30 03:21:50 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Comment 1 Ben Beasley 2026-09-30 07:04:53 UTC
(In reply to Ganesh from comment #0)
> Remote exploitation of the attack is possible.

This is just silly. The only way this could be exploited remotely is if someone decides to build a system that takes the initial parameters for this audio oscillator written in C from the network. Sure, that’s possible, but by that logic, every bug that can be triggered by passing a C function bad parameters is remotely exploitable, and so is my washing machine, because it’s possible for me to take it apart and connect a network-controlled servomotor to the temperature dial, and if I did that someone could maliciously shrink my underwear.

I don’t expect upstream to pay attention to this report, and if they do, I expect they will close it without comment or investigation due to the use of AI.

To be sure, it’s better for routines like this to perform parameter validation up front and not to explode when ill-documented limits are exceeded. I’m tracking the upstream issue, and I’ll be happy to apply a sane patch downstream if one appears. I’m still going to close this as WONTFIX because I’m not personally planning to work on a patch, and I doubt anyone else is going to bother either.


Note You need to log in before you can comment on or make changes to this bug.