Impact
The flaw resides in the ps_find_padding function of vgmstream’s VAG file handler. When the decoder processes a specially crafted VAG file, it performs an out-of-bounds read, exposing data that lies beyond the intended buffer area. This uncontrolled memory access may reveal sensitive information or cause a crash, thereby allowing denial‑of‑service or data disclosure. The weakness aligns with CWE-119 (Buffer Access Through an Out‑of‑Bound Pointer) and CWE-125 (Out‑of‑Bounds Read).
Affected Systems
The open‑source audio stream library vgmstream, specifically all builds based on or prior to revision r2117, is affected. Any installation that still employs this version of the VAG decoder without the upstream patch is vulnerable. Since no pre‑compiled binaries are listed from a vendor, users must verify their vgmstream version string and ensure that the patch is applied or a later revision is used.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating moderate severity, and the stated attack vector is remote, meaning a malicious VAG file can be supplied from a network or external source. EPSS information is not available, but the existence of a documented remote exploitation path and the lack of detection in the CISA KEV catalog nevertheless warrant swift action. An attacker can exploit the flaw simply by feeding a crafted VAG file into an application using vgmstream, causing potential memory disclosure or application instability.
OpenCVE Enrichment