{"id":"CVE-2026-105248","title":"A security flaw has been discovered in vgmstream up to r2117","summary":"A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The a…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L","cwe":["CWE-119","CWE-787"],"product":"vgmstream","affected":["vgmstream r2117"],"published":"2026-10-05","updated":"2026-10-05","sourceUpdated":"2026-10-05T08:17:15.217","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105248","references":[{"url":"https://github.com/vgmstream/vgmstream/","label":"cna@vuldb.com"},{"url":"https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b","label":"cna@vuldb.com"},{"url":"https://github.com/vgmstream/vgmstream/issues/1997","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-105248","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/976278","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413455","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/413455/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-05T08:15:34.902Z","slug":"CVE-2026-105248","body":"## Overview\n\nA security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}