CVE-2026-105250
Received Received - Intake

Divide by Zero in vgmstream Microsoft IMA Decoder

Vulnerability report for CVE-2026-105250, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulDB

Description

A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vgmstream vgmstream to r2117 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-404 The product does not release or incorrectly releases a resource before it is made available for re-use.
CWE-369 The product divides a value by zero.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a divide-by-zero issue in the vgmstream library up to version r2117. It occurs in the decode_ms_ima function of the Microsoft IMA Decoder component when processing malformed RIFF/WAVE audio files. The flaw allows attackers to cause a denial-of-service by exploiting invalid channel geometry or block size values in the file headers.

Detection Guidance

To detect this vulnerability, monitor for crashes or hangs in applications using vgmstream when processing audio files. Check for divide-by-zero errors in logs. Use tools like 'strings' or 'hexdump' to inspect RIFF/WAVE file headers for malformed channel or block size values.

Impact Analysis

If you use applications that rely on vgmstream to process untrusted audio files, an attacker could exploit this flaw to crash the application. This could disrupt services or prevent users from accessing media content. The impact is limited to denial-of-service as no code execution or data theft is possible.

Compliance Impact

This vulnerability, a divide-by-zero issue in vgmstream's Microsoft IMA Decoder, could lead to denial-of-service attacks by crashing applications processing untrusted audio files. While not directly violating GDPR or HIPAA, such crashes may disrupt systems handling sensitive data, potentially causing data processing interruptions or loss of availability. Compliance risks arise if the affected software processes personal health information (HIPAA) or personal data (GDPR) and fails to maintain availability or integrity due to the vulnerability.

Mitigation Strategies

Update vgmstream to the latest version with safeguards in decode_ms_ima(). Validate audio file headers before processing to ensure channel and block size values are positive. Restrict untrusted audio file processing to prevent exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105250. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart