[NotCVE-2026-0016] game-music-emu VGM Command Interpreter Unvalidated 0xE0 PCM Seek Offset Allows Out-of-Bounds Read and Denial of Service
Full Disclosuremailing list archivesFrom: advisories () notcve orgDate: Tue, 2 2026-10-1 06:16:37 Author: seclists.org(查看原文) 阅读量:5 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: advisories () notcve org
Date: Tue, 29 Sep 2026 10:25:18 +0200

----------------------------------------------------------------------------
NotCVE Advisory — NotCVE-2026-0016
----------------------------------------------------------------------------

[-] Summary:
An out-of-bounds read in the VGM command interpreter of game-music-emu
(libgme), the open-source video game music emulation library, allows an
attacker who supplies a crafted .vgm or .vgz file to crash the hosting
process or to have adjacent heap memory influence the rendered audio, via
a PCM seek command whose offset is never validated. CVSS:3.1 7.1
(AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H).

[-] Affected:
game-music-emu (libgme) through 0.6.5, and master as of commit fe8da4b.
Default builds; no fixed version is verified.

[-] Technical Description:
Vgm_Emu_Impl::run_commands() in gme/Vgm_Emu_Impl.cpp handles VGM command
0xE0 (cmd_pcm_seek) by building an interior pointer straight from file
content:

  case cmd_pcm_seek:
      pcm_pos = pcm_data + pos [3] * 0x1000000L + pos [2] * 0x10000L +
              pos [1] * 0x100L + pos [0];
      pos += 4;
      break;

pcm_data points into the decompressed file buffer, set by a preceding 0x67
(cmd_data_block) command. The 32-bit little-endian operand is
attacker-controlled and is compared neither against the declared
data-block size nor against data_end, so pcm_pos can be placed up to 4 GiB
past the end of the allocation. The following 0x80-0x8F (cmd_pcm_delay)
case then executes write_pcm( vgm_time, *pcm_pos++ ), dereferencing the
pointer without a bounds check of its own. The reporter's AddressSanitizer
log records a SEGV on a read at Vgm_Emu_Impl.cpp:255 in run_commands().

When the computed address is unmapped the read faults and the process
terminates; when it is mapped, the byte read becomes part of the decoded
audio, so memory adjacent to the file buffer can influence
attacker-observable output.

Reachability: the VGM emulator is part of the default build, and the
command stream runs during gme_start_track(), on the file-open path. VLC's
modules/demux/gme.c calls gme_start_track() from its demuxer Open
function, and FFmpeg links the library when built with --enable-libgme. No
authentication, privileges or configuration change are needed; the file
only has to reach a libgme consumer.

Upstream issue #165 reports a related but different overread in the same
function (unchecked command argument bytes); it is not this defect.

Weaknesses:
CWE-823: Use of Out-of-range Pointer Offset
CWE-125: Out-of-bounds Read
CAPEC-540: Overread Buffers
CAPEC-129: Pointer Manipulation

[-] Credit:
Discovered by netspacer1124 (https://github.com/netspacer1124).

[-] Full Details and Updates:
https://notcve.org/notcve/NotCVE-2026-0016

[-] Main References:
https://github.com/libgme/game-music-emu
https://raw.githubusercontent.com/libgme/game-music-emu/0.6.5/gme/Vgm_Emu_Impl.cpp
https://github.com/videolan/vlc/blob/master/modules/demux/gme.c

[-] About NotCVE:
NotCVE (https://notcve.org) assigns public, timestamped NotCVE IDs to
vulnerabilities not acknowledged by vendors. Vendor will not assign a CVE?
Request a NotCVE: https://notcve.org/form/ · Contributors:
https://notcve.org/hall/
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/

Current thread:

  • [NotCVE-2026-0016] game-music-emu VGM Command Interpreter Unvalidated 0xE0 PCM Seek Offset Allows Out-of-Bounds Read and Denial of Service advisories (Sep 30)

文章来源: https://seclists.org/fulldisclosure/2026/Sep/92
如有侵权请联系:admin#unsafe.sh