Out-of-Bounds Write Vulnerability in vgmstream TXTP File Handler
CVE-2026-105248

5.3MEDIUM

Key Information:

Vendor

vgmstream

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105248?

A security flaw has been identified in the vgmstream audio streaming library, specifically within the TXTP File Handler. This vulnerability affects versions up to r2117 and is linked to out-of-bounds write issues in the function parse_params/txtp_parse located in src/meta/txtp_parser.c. Attackers may exploit this vulnerability remotely to manipulate memory and potentially gain control over the system. Applying the patch identified as 4669d37a6af94866f6f0628678f9f90d46954e8b is essential for safeguarding against this security threat.

Affected Version(s)

vgmstream r2117

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ni-liao (VulDB User)
.