Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue. | |
| Title | vgmstream TXTP File txtp_process.c make_group_random use after free | |
| First Time appeared |
Vgmstream
Vgmstream vgmstream |
|
| Weaknesses | CWE-119 CWE-416 |
|
| CPEs | cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vgmstream
Vgmstream vgmstream |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-05T07:30:18.663Z
Reserved: 2026-10-04T17:37:11.048Z
Link: CVE-2026-105249
No data.
Status : Received
Published: 2026-10-05T08:17:15.417
Modified: 2026-10-05T08:17:15.417
Link: CVE-2026-105249
No data.
OpenCVE Enrichment
Updated: 2026-10-05T10:00:16Z
