CVE-2026-105251: vgmstream VAG File psx_decoder.c ps_find_padding out-of-bounds
A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function psfindpadding of the file src/coding/psxdecoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named 4b8316652a30d40f99ad43310bed273fd1f8a7a3. It is suggested to install a patch to address this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
vgmstreamto a version that resolves this vulnerability.Patch 4b8316652a30d40f99ad43310bed273fd1f8a7a3
Event History
Frequently Asked Questions
Which deployments are affected?
vgmstream versions up to r2117 are affected when handling VAG files through the VAG File Handler.
What must an attacker do to exploit this issue?
An attacker needs to cause vgmstream to process a manipulated VAG file. The issue is remotely reachable and requires user interaction, while no attacker privileges are required.
Is a patch available?
Yes. The identified patch is commit 4b8316652a30d40f99ad43310bed273fd1f8a7a3; installing it is recommended.