CVE-2026-105249: vgmstream TXTP File txtp_process.c make_group_random use after free
A weakness has been identified in vgmstream up to r2117. This impacts the function makegrouprandom of the file src/meta/txtpprocess.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vgmstreamto a version that resolves this vulnerability.Patch ae37662ad626254ddd96ad69ac263792d7a92024
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems using vgmstream versions up to r2117 are affected, specifically when processing TXTP files through the TXTP File Handler. Exploitation requires local access.
What access does an attacker need?
The supplied vector indicates local attack access, low attack complexity, low privileges, and user interaction. The data does not specify the exact interaction required or how a crafted TXTP file is delivered.
What is the remediation?
Apply patch ae37662ad626254ddd96ad69ac263792d7a92024. The available data does not provide a fixed release version.