Use After Free Vulnerability in vgmstream TXTP File Handler by vgmstream
CVE-2026-105249

2.4LOW

Key Information:

Vendor

vgmstream

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105249?

A vulnerability has been discovered in the vgmstream TXTP File Handler, specifically affecting the make_group_random function within the src/meta/txtp_process.c file. This issue can lead to a use after free scenario, requiring local exploitation. It is advisable to implement the provided patch (ae37662ad626254ddd96ad69ac263792d7a92024) to mitigate this risk and secure the affected implementation.

Affected Version(s)

vgmstream r2117

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ni-liao (VulDB User)
.