Your message dated Fri, 28 Aug 2026 12:18:54 +0000
with message-id <[email protected]>
and subject line Bug#1144933: fixed in libmodplug 1:0.8.9.0-4
has caused the Debian Bug report #1144933,
regarding libmodplug: CVE-2026-75904
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144933: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144933
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: libmodplug
Version: 1:0.8.9.0-3
Severity: important
Tags: security upstream
Forwarded: https://github.com/Konstanty/libmodplug/issues/103
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for libmodplug.
CVE-2026-75904[0]:
| libmodplug through 0.8.9.1 contains an out-of-bounds read in
| pat_smplooped in src/load_pat.cpp. The function validates only the
| upper bound of its sample index against MAXSMP and then subtracts
| one before indexing the 191-byte static array pat_loops, so an index
| of zero reads pat_loops[-1], one byte before the array. The index is
| the smpno field of a parsed MIDI event, which is initialised to zero
| and only later overwritten from a program-change parameter, so an
| event reaching the note test before an instrument is assigned
| carries zero. A 32-byte MIDI file supplied to the library's public
| ModPlug_Load entry point drives the path through CSoundFile::Create,
| CSoundFile::ReadMID, and MID_ReadPatterns to the read. The byte read
| out of bounds determines whether a note event is treated as looping,
| so adjacent static storage influences playback state.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-75904
https://www.cve.org/CVERecord?id=CVE-2026-75904
[1] https://github.com/Konstanty/libmodplug/issues/103
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: libmodplug
Source-Version: 1:0.8.9.0-4
Done: Stephen Kitt <[email protected]>
We believe that the bug you reported is fixed in the latest version of
libmodplug, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Stephen Kitt <[email protected]> (supplier of updated libmodplug package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 28 Aug 2026 13:57:00 +0200
Source: libmodplug
Architecture: source
Version: 1:0.8.9.0-4
Distribution: unstable
Urgency: medium
Maintainer: Stephen Kitt <[email protected]>
Changed-By: Stephen Kitt <[email protected]>
Closes: 1008097 1144933
Changes:
libmodplug (1:0.8.9.0-4) unstable; urgency=medium
.
* Update upstream links to point to
https://github.com/Konstanty/libmodplug; development there appears to
have stalled but it’s where issues and PRs are tracked.
Closes: #1008097.
* Apply candidate patch to fix OOB read. Closes: #1144933;
CVE-2026-75904.
* Apply candidate fix for mLoopCount global setting.
* Drop “Rules-Requires-Root: no” since it’s now the default.
* Drop “Priority: optional” since it’s now the default.
* Standards-Version 4.7.4, no further change needed.
* Bump to debhelper compatibility level 14.
* Delete obsolete xmms-modplug-related files.
Checksums-Sha1:
2f170167b2bb6a6f67712be004304efd2094678a 1948 libmodplug_0.8.9.0-4.dsc
c856c95030cc8530c0f853ceba50060c6a8c0c82 11732
libmodplug_0.8.9.0-4.debian.tar.xz
f5d527ea7c5f49bf4de89651a3e497b5473030af 6362
libmodplug_0.8.9.0-4_source.buildinfo
Checksums-Sha256:
8c5a020cab55be5d16b5cb14e503e8f316fe3d3eb0333aa93ab3be9ff980d81d 1948
libmodplug_0.8.9.0-4.dsc
771353752e278f833520d081b66b65a1ef87f70fe9a55c4def72ceaf3783be89 11732
libmodplug_0.8.9.0-4.debian.tar.xz
5d1f658b6cf654451d7b2873ef10f0b8363f6803d4b79b6060346bbd183fda70 6362
libmodplug_0.8.9.0-4_source.buildinfo
Files:
9026b41d706abd2c7c31d8e4380a5977 1948 libs optional libmodplug_0.8.9.0-4.dsc
52a9ca39423a0d2b81ceab2af5c18a07 11732 libs optional
libmodplug_0.8.9.0-4.debian.tar.xz
82c665712cd58238f243759eddfd5683 6362 libs optional
libmodplug_0.8.9.0-4_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEnPVX/hPLkMoq7x0ggNMC9Yhtg5wFAmqRd7MACgkQgNMC9Yht
g5x7ww/+Ii6KVhvtBZsGjn9cTwLhHdAHJqhllrxmQ1OzjNmB7kWFDjuMuvYGIFfc
m2IDiGtZ00c8KByfENIZnK8o2mogpoLfJ6wHmGkm905LjRWxQvb/EhK00M2YQlHn
0vhRTVB2OtzlcCW9V/bWkR9ciQQTzNS3EMGgF1TypfFn2TfRRu5Z2oze5jGt5mKb
yjtwcqRcuUet6lqWAuQnr7L6Qu6snypZseX9yojQwue8VAf9n7FgB8rHM/rMyx3G
arj+bgX9HprlKnj7QeDmFwp45XJM3B2/fYVgNLUw9qMnODbWCxjM2wCEL8vpz7/F
m9yO897q2Las4T3ZwhZAYQb1HF4GZACTVCTeHJTxHXr3L/H9J3leUXwmZ/qtiLmU
kLjwEKCfUcbW+ZqnAcyhMQvCP3AWNVRIIwXNVVQUhqVOGhzNYoFCDCxMbBZo5GpF
lznTXC7UqVEUq+7eLCSrS+jivorwWxsUKKAEngexBpqGIsKkBieAyQ9o77vixUPx
GLuwLJUKnQMr6svf/m7xkzOh+/Iuq1VdaOTJ+4UAWye93WUF1WUZfVryd0RI1Qbj
HNdeZqOZoFLU8BlzXD7z4KDUk3pChAXxct1plnOHPNuM9h0Ch33+6BLsRRXB9aoI
ybUAjPp+nGdqUlYwBml7Ai5u/jxrDaa+It9wOyVojS+HdSV/NG8=
=bnqE
-----END PGP SIGNATURE-----
pgpr2THMHHnYP.pgp
Description: PGP signature
--- End Message ---