Description
A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.
Published: 2026-10-05
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Out-of-Bounds Write
Action: Apply Patch
AI Analysis

Impact

An out-of-bounds write was discovered in the TXT file parser of vgmstream. The flaw occurs in the parse_params/txtp_parse function within src/meta/txtp_parser.c and allows an attacker to write beyond the bounds of a buffer, potentially corrupting memory or causing a crash. Because the vulnerable code processes externally supplied TXT files, the attack can be remote by providing malicious files over a network or other remote channels.

Affected Systems

All released builds of vgmstream up to revision r2117 are affected. The vulnerability is present in all branches that include the old implementation of the TXT file handler until the patch commit 4669d37a6af94866f6f0628678f9f90d46954e8b is applied, which updates the library to r2118 or later.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, but the advisory explicitly states that the attacker may launch the attack remotely, raising concern for deployments that accept untrusted input. The vulnerability is not listed in the CISA KEV catalog, so no large-scale exploitation is known. If exploited, the out-of-bounds condition could lead to denial of service or, with advanced techniques, potential code execution through memory corruption.

Generated by OpenCVE AI on October 5, 2026 at 08:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the patch commit 4669d37a6af94866f6f0628678f9f90d46954e8b which updates vgmstream to revision r2118 or later.
  • Disable or block the processing of TXT files from untrusted sources until the patch is applied, for example by removing the file handler or restricting file inputs in configuration.
  • Monitor application logs and runtime behavior for signs of buffer overflow or crashes, and verify that the vulnerability no longer triggers after patching.

Generated by OpenCVE AI on October 5, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 07:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.
Title vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write
First Time appeared Vgmstream
Vgmstream vgmstream
Weaknesses CWE-119
CWE-787
CPEs cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
Vendors & Products Vgmstream
Vgmstream vgmstream
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Vgmstream Vgmstream
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T13:24:18.469Z

Reserved: 2026-10-04T17:37:07.514Z

Link: CVE-2026-105248

cve-icon Vulnrichment

Updated: 2026-10-05T13:24:15.532Z

cve-icon NVD

Status : Received

Published: 2026-10-05T08:17:15.217

Modified: 2026-10-05T14:17:19.530

Link: CVE-2026-105248

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T09:00:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-787

    Out-of-bounds Write