Description
A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue.
Published: 2026-10-05
Score: 2.4 Low
EPSS: n/a
KEV: No
Impact: Local use‑after‑free vulnerability in vgmstream TXTP file processing
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the make_group_random function of the TXTP file handler. A local attacker can trigger a use‑after‑free condition that may enable arbitrary memory access or a program crash. The flaw does not provide remote code execution or elevation of privilege but can be leveraged to destabilize applications that load malicious TXTP files.

Affected Systems

The flaw affects the open‑source project vgmstream, version r2117 and earlier. The affected component is src/meta/txtp_process.c within the TXTP file handling module. Users running any vgmstream build prior to the patch commit ae37662ad626254ddd96ad69ac263792d7a92024 are at risk.

Risk and Exploitability

With a CVSS score of 2.4 the vulnerability is considered low impact. No EPSS score is available, and it is not listed in the CISA KEV catalog. The attack requires local access and file manipulation. While exploitation could cause application instability or denial of service, it does not grant arbitrary code execution.

Generated by OpenCVE AI on October 5, 2026 at 09:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update to the patched commit ae37662ad626254ddd96ad69ac263792d7a92024 or later version of vgmstream
  • If an update is not immediately possible, restrict the use of the vgmstream library to trusted, non‑exposed environments and enforce least‑privilege execution
  • Monitor logs for signs of abnormal crashes or memory errors that could indicate exploitation attempts

Generated by OpenCVE AI on October 5, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue.
Title vgmstream TXTP File txtp_process.c make_group_random use after free
First Time appeared Vgmstream
Vgmstream vgmstream
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:*
Vendors & Products Vgmstream
Vgmstream vgmstream
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Vgmstream Vgmstream
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T07:30:18.663Z

Reserved: 2026-10-04T17:37:11.048Z

Link: CVE-2026-105249

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T08:17:15.417

Modified: 2026-10-05T08:17:15.417

Link: CVE-2026-105249

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T09:30:10Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free