CVE-2026-105249Medium· 4.8▾ SunlitA weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-92880Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-92881Medium· 4.3A security vulnerability has been detected in vgmstream
CVE-2026-92879Medium· 4.3A security flaw has been discovered in vgmstream up to r2117
CVE-2026-105251Medium· 6.3vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds
CVE-2026-105248Medium· 6.3A security flaw has been discovered in vgmstream up to r2117
CVE-2026-86514Medium· 6.3A weakness has been identified in vgmstream up to r2117