Out-of-Bounds Read in VAG File Handler of vgmstream from the Vendor vgmstream
CVE-2026-105251

5.3MEDIUM

Key Information:

Vendor

vgmstream

Status
Vendor
CVE Published:
5 October 2026

What is CVE-2026-105251?

A vulnerability exists in vgmstream up to version r2117 within the psx_decoder.c file, specifically in the ps_find_padding function. This issue can lead to an out-of-bounds read, potentially allowing remote attackers to exploit the vulnerability. To mitigate this risk, it is recommended to apply the provided patch identified by commit 4b8316652a30d40f99ad43310bed273fd1f8a7a3.

Affected Version(s)

vgmstream r2117

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ni-liao (VulDB User)
.