Sceawere
Vulnerability Detail
CVE-2026-105251UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
vgmstream Out-of-Bounds Read Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 10h ago
- Vendor
- n/a
- Product
- vgmstream
- Attack Type
- Out-of-Bounds Read
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named 4b8316652a30d40f99ad43310bed273fd1f8a7a3. It is suggested to install a patch to address this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-05T09:17:11.563Z",
"pubdate": "2026-10-05T09:17:11.563Z",
"executiveSummary": "A critical out-of-bounds read vulnerability exists in the VAG file handler of vgmstream up to version r2117. This flaw is located within the ps_find_padding function in src/coding/psx_decoder.c and enables an attacker to trigger memory access violations.\nThe vulnerability is remotely exploitable, allowing an unauthenticated attacker to supply a maliciously crafted VAG file to an application utilizing the affected library. Successful exploitation can lead to information disclosure or application crashes, potentially resulting in a denial-of-service state.\nThe risk is primarily associated with the unsafe handling of file metadata or buffer offsets during the decoding process of PSX-based audio formats. Users are advised to update to a version containing the official patch identified as 4b8316652a30d40f99ad43310bed273fd1f8a7a3 to remediate this security risk.",
"technicalDetails": "The vulnerability resides in the ps_find_padding function within src/coding/psx_decoder.c, which is responsible for identifying padding bytes in VAG audio files. The root cause of this flaw is insufficient bounds checking when reading from the input data buffer during the parsing process.\nWhen processing a VAG stream, the decoder attempts to locate padding sequences that signify the end of the audio data or metadata blocks. Because the function fails to adequately validate the boundaries of the input buffer against the calculated read pointer, an attacker can provide a specially crafted VAG file where the padding offset is artificially extended beyond the allocated memory segment.\nThe attack flow begins when the vgmstream library processes an untrusted VAG file. An attacker exploits this by injecting a malicious VAG header or payload that forces ps_find_padding to perform an out-of-bounds read operation. When the function accesses memory addresses outside the intended buffer range, the application may enter an undefined state. Depending on the memory layout and the specific runtime environment, this can result in the exposure of adjacent memory contents, potentially leaking sensitive data from the heap, or triggering a segmentation fault that leads to a denial-of-service condition.\nThis vulnerability is particularly dangerous because it allows for remote exploitation without requiring user authentication or specific privilege levels, provided the target application accepts and parses VAG audio files from external sources. The lack of proper sanitization or boundary verification in the decoding logic allows for an arbitrary read relative to the buffer starting point, effectively bypassing conventional memory protection mechanisms if the application continues execution after the initial access violation.\nThe patch identified as 4b8316652a30d40f99ad43310bed273fd1f8a7a3 introduces necessary boundary constraints, ensuring that the ps_find_padding function verifies the availability of bytes within the allocated memory bounds before performing any read operations, thereby preventing the out-of-bounds access attempt."
}