High severity8.2NVD Advisory· Published Sep 12, 2026
CVE-2026-89266
CVE-2026-89266
Description
stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.
Affected products
3- Range: <=1.22
Patches
Vulnerability mechanics
References
6- github.com/nothings/stb/blob/2c980bb59875b0d32144a71867fbdebb2f77cd20/stb_vorbis.cnvd
- github.com/nothings/stb/blob/2c980bb59875b0d32144a71867fbdebb2f77cd20/stb_vorbis.cnvd
- github.com/nothings/stb/issues/1928nvd
- github.com/nothings/stb/issues/1933nvd
- github.com/nothings/stb/issues/1947nvd
- www.vulncheck.com/advisories/stb-vorbis-through-1.22-heap-buffer-overflow-via-codebook-multiplicandsnvd
News mentions
0No linked articles in our index yet.