HIGHVulnerability
CVE-2026-89266
stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.
Properties
- severity
- HIGH
- score
- 8.2
- cve_id
- CVE-2026-89266
- signal_observed_at
- 2026-09-21T23:07:07+00:00
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
- published_at
- 2026-09-12T00:17:06.440
- last_modified
- 2026-09-20T01:16:31.883
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Out-of-bounds Write
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph