CVE-2026-92881

Medium severity, CVSS 4.3. EPSS: 0.6% chance of exploitation in the next 30 days.

A security vulnerability has been detected in vgmstream. The affected element is the function init_vgmstream_awb_memory of the file src/meta/awb.c of the component AWB parser. Such manipulation leads to divide by zero. The attack can be executed remotely. The name of the patch is ae37662ad626254ddd96ad69ac263792d7a92024. A patch should be applied to remediate this issue.

Published 2026-09-17. Last modified 2026-09-23.