Junglewise Threat Intelligence

CVE-2026-92881: vgmstream divide-by-zero in AWB parser

CVE-2026-92881 · Severity: medium · CVSS 4.3 · Published 2026-09-17

Technologies: Vgmstream. Vendors: Vgmstream.

Executive brief

vgmstream is a widely-used open-source library for playing streamed audio formats from video games. A divide-by-zero flaw in the AWB audio file parser can crash the application when processing a maliciously crafted audio file, causing denial of service to any software using the library to play game audio.

Technical details

The vulnerability is a divide-by-zero error in the init_vgmstream_awb_memory function within the AWB parser component (src/meta/awb.c). The flaw is triggered when processing specially crafted AWB audio files with zero-valued parameters that bypass input validation. The attack is remotely exploitable—an attacker can craft a malicious AWB file and provide it to a user or service for parsing, causing immediate application crash. No authentication is required. The patch (commit ae37662ad626254ddd96ad69ac263792d7a92024) is available and addresses multiple undefined behavior, buffer, and integer overflow issues in the parser.

Affected products

  • vgmstream vgmstream <commit ae37662ad626254ddd96ad69ac263792d7a92024

Timeline

  • 2026-09-17: disclosed
  • 2026-08-23: patched: Patch commit ae37662ad626254ddd96ad69ac263792d7a92024

References

Related threats