EIP-2026-103169

PRE-CVE

mpg123 pre0.59s - Invalid MP3 Header Memory Corruption

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103169. PoCs published by Gobbles Security.

AI-analyzed exploit summary This is a functional exploit for a memory corruption vulnerability in mpg123, which allows arbitrary code execution via a malformed MP3 file header. The exploit crafts a malicious MP3 file with a manipulated header and embedded shellcode, targeting specific memory addresses for different Linux distributions.

Description

mpg123 pre0.59s - Invalid MP3 Header Memory Corruption

Exploits (1)

exploitdb WORKING POC VERIFIED
by Gobbles Security · cremotelinux
https://www.exploit-db.com/exploits/22147

This is a functional exploit for a memory corruption vulnerability in mpg123, which allows arbitrary code execution via a malformed MP3 file header. The exploit crafts a malicious MP3 file with a manipulated header and embedded shellcode, targeting specific memory addresses for different Linux distributions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: mpg123 (versions affected by the vulnerability)
No auth needed
Prerequisites: Ability to deliver a malicious MP3 file to the target · Target must use mpg123 to play the file
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026