CVE-2026-105250

A security vulnerability has been detected in vgmstream up to r2117. Affected is the function decode_ms_ima of the file src/coding/ima_decoder.c of the component Microsoft IMA Decoder. Such manipulation leads to divide by zero. The attack can be executed remotely.

  • Published Oct 5, 2026
  • CVSS 5.3 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-105250 at the National Vulnerability Database