Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-47256.json"