CVE-2017-11311: Openmpt Libopenmpt

High severity, CVSS 7.8. EPSS: 1.7% chance of exploitation in the next 30 days.

soundlib/Load_psm.cpp in OpenMPT through 1.26.12.00 and libopenmpt before 0.2.8461-beta26 has a heap buffer overflow with the potential for arbitrary code execution via a crafted PSM File that triggers use of the same sample slot for two samples.

Affected products

  • Openmpt Libopenmpt: up to and including 0.2.8414
  • Openmpt Openmpt: up to and including 1.26.12.00

Published 2017-07-17. Last modified 2026-06-17.