← Back to CVE List
CVE-2026-105248NVD
Vulnerability Summary
A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.
CVSS v4.0 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 6.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- n/a vgmstream >= r2117
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/413455
- https://vuldb.com/vuln/413455/cti
- https://vuldb.com/cve/CVE-2026-105248
- https://vuldb.com/submit/976278
- https://github.com/vgmstream/vgmstream/issues/1997
- https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b
- https://github.com/vgmstream/vgmstream/