Executive brief
Snes9X is a popular emulator used to play Super Nintendo games on modern computers. A vulnerability in how the software handles game modification files (UPS patches) allows a specially crafted file to crash the application. Because the emulator automatically looks for and applies these patch files when a game is loaded, a user could be affected simply by placing a malicious file in the same folder as a game ROM.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the UPS patching routine within `memmap.cpp`. The root cause is a lack of bounds checking on the `relative` offset variable during the XOR loop in the `ReadUPSPatch` function. While the initial ROM size is validated, the accumulated offset derived from `XPSdecode` can exceed the allocated `Memory.ROM` buffer (MAX_ROM_SIZE). An attacker can trigger this by providing a crafted .ups file alongside a matching ROM; the emulator's auto-patching logic will process the file without user intervention. This leads to heap corruption and a denial of service (crash), though code execution is theoretically possible if memory protections like ASLR/DEP are bypassed. The issue was addressed in commit 96b3661 by adding a bounds check to the loop condition.
Affected products
- Snes9X team Snes9X 1.63
Timeline
- 2026-04-03: disclosed: Issue reported to vendor via GitHub
- 2026-04-06: patched: Fix committed to repository
- 2026-06-17: advisory: Public disclosure and CVE assignment