← Back to CVE List
CVE-2026-105249NVD
Vulnerability Summary
A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue.
CVSS v4.0 Base Metrics — Score 2.4 (LOW)
Attack VectorLocal
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionPassive
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 4.8 (MEDIUM)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- n/a vgmstream >= r2117
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/413456
- https://vuldb.com/vuln/413456/cti
- https://vuldb.com/cve/CVE-2026-105249
- https://vuldb.com/submit/976279
- https://github.com/vgmstream/vgmstream/issues/1998
- https://github.com/vgmstream/vgmstream/pull/2008
- https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024
- https://github.com/vgmstream/vgmstream/