CVE-2026-105248: vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write

Published Oct 5, 2026
·
Updated

A security flaw has been discovered in vgmstream up to r2117. This affects the function parseparams/txtpparse of the file src/meta/txtpparser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.

Affected Software

1 affected component
vgmstream vgmstream<=r2117

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade vgmstream to a version that resolves this vulnerability.

    Patch 4669d37a6af94866f6f0628678f9f90d46954e8b

Event History

Oct 5, 2026
CVE Published
via MITRE·07:15 AM
Data Sourced
via MITRE·07:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments should be prioritized for remediation?

Prioritize vgmstream installations at r2117 or earlier that process TXTP files, especially where files can originate from remote or untrusted sources. The issue is remotely reachable and can affect confidentiality, integrity, and availability.

2

What does exploitation require?

An attacker needs to provide a manipulated TXTP file for processing by the affected TXTP File Handler. The vector indicates user interaction is required, so exploitation depends on a user or workflow opening or otherwise processing the malicious file.

3

How can I determine whether I am affected, and what is the available fix?

Installations running vgmstream up to r2117 are affected. Apply the patch identified as 4669d37a6af94866f6f0628678f9f90d46954e8b.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203