- Package:
- src:libmodplug
- Source:
- src:libmodplug
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-28 12:21:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for libmodplug. CVE-2026-75904[0]: | libmodplug through 0.8.9.1 contains an out-of-bounds read in | pat_smplooped in src/load_pat.cpp. The function validates only the | upper bound of its sample index against MAXSMP and then subtracts | one before indexing the 191-byte static array pat_loops, so an index | of zero reads pat_loops[-1], one byte before the array. The index is | the smpno field of a parsed MIDI event, which is initialised to zero | and only later overwritten from a program-change parameter, so an | event reaching the note test before an instrument is assigned | carries zero. A 32-byte MIDI file supplied to the library's public | ModPlug_Load entry point drives the path through CSoundFile::Create, | CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read | out of bounds determines whether a note event is treated as looping, | so adjacent static storage influences playback state. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-75904 https://www.cve.org/CVERecord?id=CVE-2026-75904 [1] https://github.com/Konstanty/libmodplug/issues/103 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of libmodplug, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1144933@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Stephen Kitt <skitt@debian.org> (supplier of updated libmodplug package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Fri, 28 Aug 2026 13:57:00 +0200 Source: libmodplug Architecture: source Version: 1:0.8.9.0-4 Distribution: unstable Urgency: medium Maintainer: Stephen Kitt <skitt@debian.org> Changed-By: Stephen Kitt <skitt@debian.org> Closes: 1008097 1144933 Changes: libmodplug (1:0.8.9.0-4) unstable; urgency=medium . * Update upstream links to point to https://github.com/Konstanty/libmodplug; development there appears to have stalled but it’s where issues and PRs are tracked. Closes: #1008097. * Apply candidate patch to fix OOB read. Closes: #1144933; CVE-2026-75904. * Apply candidate fix for mLoopCount global setting. * Drop “Rules-Requires-Root: no” since it’s now the default. * Drop “Priority: optional” since it’s now the default. * Standards-Version 4.7.4, no further change needed. * Bump to debhelper compatibility level 14. * Delete obsolete xmms-modplug-related files. Checksums-Sha1: 2f170167b2bb6a6f67712be004304efd2094678a 1948 libmodplug_0.8.9.0-4.dsc c856c95030cc8530c0f853ceba50060c6a8c0c82 11732 libmodplug_0.8.9.0-4.debian.tar.xz f5d527ea7c5f49bf4de89651a3e497b5473030af 6362 libmodplug_0.8.9.0-4_source.buildinfo Checksums-Sha256: 8c5a020cab55be5d16b5cb14e503e8f316fe3d3eb0333aa93ab3be9ff980d81d 1948 libmodplug_0.8.9.0-4.dsc 771353752e278f833520d081b66b65a1ef87f70fe9a55c4def72ceaf3783be89 11732 libmodplug_0.8.9.0-4.debian.tar.xz 5d1f658b6cf654451d7b2873ef10f0b8363f6803d4b79b6060346bbd183fda70 6362 libmodplug_0.8.9.0-4_source.buildinfo Files: 9026b41d706abd2c7c31d8e4380a5977 1948 libs optional libmodplug_0.8.9.0-4.dsc 52a9ca39423a0d2b81ceab2af5c18a07 11732 libs optional libmodplug_0.8.9.0-4.debian.tar.xz 82c665712cd58238f243759eddfd5683 6362 libs optional libmodplug_0.8.9.0-4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEnPVX/hPLkMoq7x0ggNMC9Yhtg5wFAmqRd7MACgkQgNMC9Yht g5x7ww/+Ii6KVhvtBZsGjn9cTwLhHdAHJqhllrxmQ1OzjNmB7kWFDjuMuvYGIFfc m2IDiGtZ00c8KByfENIZnK8o2mogpoLfJ6wHmGkm905LjRWxQvb/EhK00M2YQlHn 0vhRTVB2OtzlcCW9V/bWkR9ciQQTzNS3EMGgF1TypfFn2TfRRu5Z2oze5jGt5mKb yjtwcqRcuUet6lqWAuQnr7L6Qu6snypZseX9yojQwue8VAf9n7FgB8rHM/rMyx3G arj+bgX9HprlKnj7QeDmFwp45XJM3B2/fYVgNLUw9qMnODbWCxjM2wCEL8vpz7/F m9yO897q2Las4T3ZwhZAYQb1HF4GZACTVCTeHJTxHXr3L/H9J3leUXwmZ/qtiLmU kLjwEKCfUcbW+ZqnAcyhMQvCP3AWNVRIIwXNVVQUhqVOGhzNYoFCDCxMbBZo5GpF lznTXC7UqVEUq+7eLCSrS+jivorwWxsUKKAEngexBpqGIsKkBieAyQ9o77vixUPx GLuwLJUKnQMr6svf/m7xkzOh+/Iuq1VdaOTJ+4UAWye93WUF1WUZfVryd0RI1Qbj HNdeZqOZoFLU8BlzXD7z4KDUk3pChAXxct1plnOHPNuM9h0Ch33+6BLsRRXB9aoI ybUAjPp+nGdqUlYwBml7Ai5u/jxrDaa+It9wOyVojS+HdSV/NG8= =bnqE -----END PGP SIGNATURE-----