CVE-2026-105251Medium· 6.3▾ SunlitA vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bou…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named 4b8316652a30d40f99ad43310bed273fd1f8a7a3. It is suggested to install a patch to address this issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-105248Medium· 6.3A security flaw has been discovered in vgmstream up to r2117
CVE-2026-105249Medium· 4.8A weakness has been identified in vgmstream up to r2117
CVE-2026-92880Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-86514Medium· 6.3A weakness has been identified in vgmstream up to r2117
CVE-2026-105250Medium· 4.3A security vulnerability has been detected in vgmstream up to r2117
CVE-2026-92881Medium· 4.3A security vulnerability has been detected in vgmstream