A vulnerability, identified as NotCVE-2026-0017, has been disclosed in the AY file loader of game-music-emu (libgme) versions 0.6.5 and earlier. This security flaw involves a NULL pointer dereference that can be triggered when a crafted .ay file is processed. If exploited, an attacker can cause a denial of service (DoS) by crashing any application utilizing the library for music playback, including popular media players like VLC, Kodi, and Audacious.
The technical root cause lies in the get_data() function, which fails to validate relative offsets, potentially returning a NULL value that is subsequently passed to a memcpy operation. This leads to a segmentation fault during track initialization. Although the vulnerability currently results only in a process crash without direct code execution, it highlights a lack of proper return value checking in the library's AY handler.
Top comments (0)