Sceawere

Vulnerability Detail

CVE-2026-105248UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

vgmstream TXTP Out-of-Bounds Write

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
11h ago
Vendor
n/a
Product
vgmstream
Attack Type
Out-of-bounds Write
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in vgmstream up to r2117. This affects the function parse_params/txtp_parse of the file src/meta/txtp_parser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-05T08:17:15.217Z",
  "pubdate": "2026-10-05T08:17:15.217Z",
  "executiveSummary": "A critical out-of-bounds write vulnerability exists within the TXTP File Handler component of vgmstream up to version r2117.\nThe vulnerability resides in the parse_params/txtp_parse function located in src/meta/txtp_parser.c.\nThis flaw allows a remote attacker to trigger an out-of-bounds memory write by supplying a malformed TXTP file, which can lead to memory corruption, potential code execution, or application crashes.\nThe risk is significant due to the ability to launch the attack remotely, as parsing untrusted audio metadata files is a common operation in applications utilizing vgmstream.\nExploitation does not require prior authentication, making the attack vector highly accessible if an adversary can deliver a malicious file to a target system or user.",
  "technicalDetails": "The vulnerability is an out-of-bounds (OOB) write originating from improper input validation within the TXTP parsing logic. Specifically, the function parse_params in src/meta/txtp_parser.c fails to adequately verify the boundaries of input parameters provided within a TXTP file before writing them to memory buffers.\nThe TXTP file format is designed to describe how audio data should be parsed or combined. During the parsing process, the handler extracts parameters from the file to configure subsequent processing steps. If the metadata within the TXTP file defines parameters that exceed the expected size or constraints, the parser calculates write offsets based on these malicious values without sufficient bounds checking.\nWhen an attacker crafts a malicious TXTP file, they can influence the parameters consumed by the parser. During the execution of txtp_parse, these parameters are used to determine where data is written into an internal buffer. By supplying values that induce an offset calculation outside the intended memory region, the attacker forces the application to write data to arbitrary memory locations adjacent to the target buffer.\nThe attack flow proceeds as follows: First, the attacker delivers a specially crafted TXTP file to a system utilizing an affected version of vgmstream. Second, when the application attempts to process or open the malicious file, the TXTP File Handler invokes the vulnerable parse_params/txtp_parse function. Third, the function parses the metadata, including the malformed parameters. Fourth, the lack of input sanitization leads to an OOB write operation, overwriting critical data structures or memory segments with attacker-controlled content.\nThe impact of this OOB write is severe; successful exploitation can result in immediate termination of the process (Denial of Service) or, depending on the memory layout and the nature of the overwritten data, potentially facilitate remote code execution by corrupting function pointers or other sensitive control flow data. The vulnerability is exploitable remotely, as the parser is often invoked when processing audio files from untrusted sources."
}
CVE-2026-105248: vgmstream TXTP Out-of-Bounds Write (MEDIUM Severity, CVSS: 6.3) | Sceawere