Impact
The vulnerability resides in the make_group_random function of the TXTP file handler. A local attacker can trigger a use‑after‑free condition that may enable arbitrary memory access or a program crash. The flaw does not provide remote code execution or elevation of privilege but can be leveraged to destabilize applications that load malicious TXTP files.
Affected Systems
The flaw affects the open‑source project vgmstream, version r2117 and earlier. The affected component is src/meta/txtp_process.c within the TXTP file handling module. Users running any vgmstream build prior to the patch commit ae37662ad626254ddd96ad69ac263792d7a92024 are at risk.
Risk and Exploitability
With a CVSS score of 2.4 the vulnerability is considered low impact. No EPSS score is available, and it is not listed in the CISA KEV catalog. The attack requires local access and file manipulation. While exploitation could cause application instability or denial of service, it does not grant arbitrary code execution.
OpenCVE Enrichment