CVE-2026-89266 | CVSS: 8.2 | 严重级别: HIGH
stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.
参考链接:
• https://github.com/nothings/stb
• https://github.com/nothings/stb/blob/2c980bb59875b0d32144a71867fbdebb2f77cd20/st
• https://github.com/nothings/stb/blob/2c980bb59875b0d32144a71867fbdebb2f77cd20/st
📌 数据来源: NVD 官方
⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。