← Back to CVE List
CVE-2026-105251NVD
Vulnerability Summary
A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named 4b8316652a30d40f99ad43310bed273fd1f8a7a3. It is suggested to install a patch to address this issue.
CVSS v4.0 Base Metrics — Score 5.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionPassive
Confidentiality (Vulnerable System)Low
Integrity (Vulnerable System)Low
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 6.3 (MEDIUM)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionRequired
ScopeUnchanged
ConfidentialityLow
IntegrityLow
AvailabilityLow
Affected & Patched Versions
- n/a vgmstream >= r2117
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/413458
- https://vuldb.com/vuln/413458/cti
- https://vuldb.com/cve/CVE-2026-105251
- https://vuldb.com/submit/976281
- https://github.com/vgmstream/vgmstream/issues/2000
- https://github.com/vgmstream/vgmstream/pull/2001
- https://github.com/vgmstream/vgmstream/commit/4b8316652a30d40f99ad43310bed273fd1f8a7a3
- https://github.com/vgmstream/vgmstream/