Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. A vulnerability was detected in Nothings stb up to 2c980bb59875b0d32144a71867fbdebb2f77cd20. The impacted element is the function hexwave_init in the library stb_hexwave.h. Performing a manipulation of the argument width/oversample results in integer overflow. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
(In reply to Ganesh from comment #0) > Remote exploitation of the attack is possible. This is just silly. The only way this could be exploited remotely is if someone decides to build a system that takes the initial parameters for this audio oscillator written in C from the network. Sure, that’s possible, but by that logic, every bug that can be triggered by passing a C function bad parameters is remotely exploitable, and so is my washing machine, because it’s possible for me to take it apart and connect a network-controlled servomotor to the temperature dial, and if I did that someone could maliciously shrink my underwear. I don’t expect upstream to pay attention to this report, and if they do, I expect they will close it without comment or investigation due to the use of AI. To be sure, it’s better for routines like this to perform parameter validation up front and not to explode when ill-documented limits are exceeded. I’m tracking the upstream issue, and I’ll be happy to apply a sane patch downstream if one appears. I’m still going to close this as WONTFIX because I’m not personally planning to work on a patch, and I doubt anyone else is going to bother either.