Sceawere
Vulnerability Detail
CVE-2026-105249UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Use-After-Free in vgmstream TXTP
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.8
- Creation Date
- 11h ago
- Vendor
- n/a
- Product
- vgmstream
- Attack Type
- Use After Free
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.8",
"pubDate": "2026-10-05T08:17:15.417Z",
"pubdate": "2026-10-05T08:17:15.417Z",
"executiveSummary": "A critical use-after-free vulnerability exists in the vgmstream library, specifically within the TXTP file handler component.\nThe flaw, affecting versions up to r2117, stems from improper memory management during the processing of TXTP metadata structures.\nThe vulnerability is triggered within the make_group_random function in src/meta/txtp_process.c.\nSuccessful exploitation requires local access and the ability to provide a specifically crafted TXTP file to the vulnerable application.\nThe impact of this memory corruption includes potential application crashes, denial-of-service, or the theoretical execution of arbitrary code if the memory heap is manipulated by an attacker to redirect control flow.\nAs a local attack vector, it poses a risk primarily to users or automated systems processing untrusted or malicious audio metadata files.",
"technicalDetails": "The vulnerability is a use-after-free (UAF) condition located in src/meta/txtp_process.c within the make_group_random function of the vgmstream TXTP file handler.\nThe root cause involves an object being prematurely deallocated or cleared from memory while a pointer to that memory remains active and is subsequently dereferenced by the application.\nIn the context of vgmstream's TXTP processing, the make_group_random function manages complex grouping logic for audio playback. When parsing metadata, if the logic encounters a specific sequence or malformed structure within the TXTP definition, it may inadvertently free the memory associated with a grouping structure or list item before all references to that object are nullified.\nThe exploitation flow begins with the delivery of a malicious TXTP file to a host running an affected version of vgmstream. When the library processes this file, the make_group_random function performs an allocation for an object intended to represent a random group. Due to the flaw, a secondary operation or error-handling path triggers a deallocation of this memory block without ensuring that subsequent logic in the function no longer attempts to access the memory location.\nUpon reaching the dangling pointer, the application attempts to read from or write to the freed memory region. If an attacker can control the contents of the heap—a technique known as heap grooming—they may replace the freed memory with attacker-supplied data. This allows for the manipulation of function pointers or sensitive metadata that the application subsequently utilizes, potentially leading to arbitrary code execution if the application's instruction pointer is directed to attacker-controlled memory.\nThe vulnerability is restricted to a local attack vector, as the attacker must provide the malicious file to the local instance of vgmstream. It does not require network interaction or specialized privileges beyond the ability to execute the application with the malicious input. The security impact is severe, as memory corruption vulnerabilities often lead to complete application compromise or persistent denial-of-service."
}