THREAT OPS › Threat News › [NVD] CVE-2026-89266 (HIGH 8.2) — stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, c
[NVD] CVE-2026-89266 (HIGH 8.2) — stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, c
CVE-2026-89266 CVSS: 8.2 HIGH Published: 2026-09-12T00:17:06.440
stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size is truncated from size_t to int. Attackers can craft a malicious Ogg Vorbis file with large entries and dimensions values to trigger out-of-bounds writes, causing process crashes or heap corruption.
Indicators of compromise
- CVE-2026-89266cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-89266