Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <179067069848.3669815.17711523371311619649@notcve.org>
Date: Tue, 29 Sep 2026 10:31:38 +0200
From: advisories@...cve.org
To: oss-security@...ts.openwall.com
Subject: [NotCVE-2026-0019] game-music-emu through 0.6.5 VGM Command
 Interpreter Missing Operand Length Check Allows Heap Out-of-Bounds Read

----------------------------------------------------------------------------
NotCVE Advisory — NotCVE-2026-0019
----------------------------------------------------------------------------

[-] Summary:
An out-of-bounds read in the VGM command interpreter of game-music-emu
(libgme), the open-source video game music emulation library, allows an
attacker who supplies a crafted .vgm or .vgz file to read heap memory past
the end of the buffer holding the file. The read happens as soon as
playback begins. CVSS:3.1 5.4 (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L).

[-] Affected:
game-music-emu (libgme) through 0.6.5 (present in 0.6.0, 0.6.3 and 0.6.5),
and master as of commit fe8da4b. Default builds; no fixed version is
verified.

[-] Technical Description:
The command loop of Vgm_Emu_Impl::run_commands() (gme/Vgm_Emu_Impl.cpp) is
bounded only by

  while ( vgm_time < end_time && pos < data_end )

which validates the position of the opcode byte and nothing else. Each
opcode handler then fetches its operands from pos unconditionally. The
source records the gap in a TODO at the loop head: "be sure there are
enough bytes left in stream for particular command so we don't read past
end".

When a command stream ends right after an opcode byte, the operand fetch
crosses the end of the allocation made by Gme_File::load_(). Maximum
over-read per handler:

  - PSG and Game Gear register writes (*pos++): 1 byte
  - 16-bit delay 0x61 (pos[0], pos[1]): up to 2 bytes
  - YM2413 and YM2612 register writes: up to 2 bytes
  - PCM seek 0xE0 (pos[0] .. pos[3]): up to 4 bytes
  - data block header 0x67 (pos[1], get_le32( pos + 2 )): up to 6 bytes

The bytes read are consumed as sound-chip register data, so adjacent heap
contents can influence the decoded audio (limited, indirect disclosure).
AddressSanitizer aborts on the over-read; the researcher's two
proof-of-concept files reproduce it at two sites (a trailing 0x50 PSG
write and a trailing 0x67 data block header). Under a standard allocator a
read of this size normally stays within the same chunk, so a crash is
layout-dependent rather than reliable. No write, length control or code
execution is shown.

Reachability: VGM/VGZ support is in the default build. FFmpeg's
libavformat/libgme.c calls gme_open_data() and then gme_start_track()
inside read_header_gme(), so a server-side transcoder reaches the defect
while merely reading a file's header. VLC exposes the library through its
gme demux module, which handles VGM and VGZ.

Weaknesses:
CWE-125: Out-of-bounds Read
CWE-126: Buffer Over-read
CAPEC-540: Overread Buffers

[-] Credit:
Discovered by netspacer1124 (https://github.com/netspacer1124).

[-] Full Details and Updates:
https://notcve.org/notcve/NotCVE-2026-0019

[-] Main References:
https://github.com/libgme/game-music-emu
https://raw.githubusercontent.com/libgme/game-music-emu/0.6.5/gme/Vgm_Emu_Impl.cpp
https://ffmpeg.org/doxygen/5.1/libgme_8c_source.html

[-] About NotCVE:
NotCVE (https://notcve.org) assigns public, timestamped NotCVE IDs to
vulnerabilities not acknowledged by vendors. Vendor will not assign a CVE?
Request a NotCVE: https://notcve.org/form/ · Contributors:
https://notcve.org/hall/

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.