CVE-2026-105248: vgmstream TXTP File txtp_parser.c txtp_parse out-of-bounds write
A security flaw has been discovered in vgmstream up to r2117. This affects the function parseparams/txtpparse of the file src/meta/txtpparser.c of the component TXTP File Handler. The manipulation results in out-of-bounds write. The attack may be launched remotely. The patch is identified as 4669d37a6af94866f6f0628678f9f90d46954e8b. It is best practice to apply a patch to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vgmstreamto a version that resolves this vulnerability.Patch 4669d37a6af94866f6f0628678f9f90d46954e8b
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Prioritize vgmstream installations at r2117 or earlier that process TXTP files, especially where files can originate from remote or untrusted sources. The issue is remotely reachable and can affect confidentiality, integrity, and availability.
What does exploitation require?
An attacker needs to provide a manipulated TXTP file for processing by the affected TXTP File Handler. The vector indicates user interaction is required, so exploitation depends on a user or workflow opening or otherwise processing the malicious file.
How can I determine whether I am affected, and what is the available fix?
Installations running vgmstream up to r2117 are affected. Apply the patch identified as 4669d37a6af94866f6f0628678f9f90d46954e8b.