CVE-2026-105838
Deferred Deferred - Pending Action

Heap Out-of-Bounds Read in libmikmod IT Loader

Vulnerability report for CVE-2026-105838, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: VulnCheck

Description

libmikmod before 3.3.14 contains a heap out-of-bounds read vulnerability in the Impulse Tracker loader load_it.c that allows attackers to read adjacent heap memory via oversized patterns. Attackers can supply a crafted IT module with more than 200 pattern rows, causing IT_ConvertTrack() to read past the itpat buffer and crash applications.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sezero libmikmod 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

libmikmod before version 3.3.14 has a heap out-of-bounds read flaw in the Impulse Tracker loader (load_it.c). Attackers can exploit this by providing a crafted IT module with over 200 pattern rows, causing IT_ConvertTrack() to read past the itpat buffer and potentially crash applications.

Detection Guidance

This vulnerability is specific to the libmikmod library and can be detected by checking the version of libmikmod installed on your system. If the version is older than 3.3.14, the system is vulnerable. Use commands like 'apt list --installed | grep libmikmod' for Debian-based systems or 'rpm -qa | grep libmikmod' for RPM-based systems to check the installed version.

Impact Analysis

This vulnerability could allow attackers to read adjacent heap memory, potentially leading to application crashes or unauthorized information disclosure. It may affect software using libmikmod to process IT module files.

Mitigation Strategies

Immediately update libmikmod to version 3.3.14 or later. For Debian-based systems, use 'sudo apt update && sudo apt upgrade libmikmod'. For RPM-based systems, use 'sudo yum update libmikmod' or 'sudo dnf update libmikmod'. Avoid using untrusted IT modules until the library is updated.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105838. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart