[CVE-2026-89266] stb_vorbis through 1.22 contains a heap buffer overflow in s

CVE-2026-89266 | CVSS: 8.2 | 严重级别: HIGH

stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.

参考链接:
https://github.com/nothings/stb
https://github.com/nothings/stb/blob/2c980bb59875b0d32144a71867fbdebb2f77cd20/st
https://github.com/nothings/stb/blob/2c980bb59875b0d32144a71867fbdebb2f77cd20/st

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部