CVE-2026-105249

Source
https://cve.org/CVERecord?id=CVE-2026-105249
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105249.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105249
Published
2026-10-05T07:30:18Z
Modified
2026-10-09T07:07:28Z
Severity
  • 2.4 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
vgmstream TXTP File txtp_process.c make_group_random use after free
Details

A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-119",
        "CWE-416"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105249.json"
}
References

Affected packages

Git / github.com/vgmstream/vgmstream

Affected ranges

Type
GIT
Repo
https://github.com/vgmstream/vgmstream
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "r2117"
        },
        {
            "last_affected": "r2117"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

Other
r2117

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105249.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "61950491203349619542819047073684110605",
            "length": 424
        },
        "id": "CVE-2026-105249-10d99fe5",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/coding/vadpcm_decoder.c",
            "function": "vadpcm_read_coefs_be"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "221741655899341405355520873656546392911",
                "55010596707300793946803163126101891753",
                "250007935213284495856374148068038265277",
                "145199981610081947813644764322382782872",
                "270589024631504215031860228612840538844",
                "190939605965985965651449036493094516727",
                "225260035090917991029688070709497173701",
                "130225355172283258812440062378973838003",
                "257346637233878023777314346350643789729",
                "115724729695296889531713382721604932772"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105249-1beb7b82",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/coding/vadpcm_decoder.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "277919035690041846310118315747702608827",
                "191579810583570283803808898342780672284",
                "254811042427858936847494700657405935726",
                "36910391587684210834934834894162261835",
                "70144175419785209738034272747536287741",
                "39795347645260067342377428989831003454",
                "220676604697613284473193676532660606270",
                "189605501174611158398520266823696678613",
                "89048848195360174446663530295313470865",
                "249519714518561596723726149552150668134",
                "142067702656514483413847377251606091935",
                "1766340400062385431205303740956760637",
                "195327080898701314406218649410002094375",
                "324407869122832018574201868759715391835",
                "9804252359644321236787373588718787382",
                "138286893271057811087629221345634609143",
                "109177262425867329259507924992864640238",
                "98149895673777243802297339806656915866",
                "276724982101181025694146884556575863946",
                "218505817112042971847568815641468985994",
                "266299874133884625758235216685082700111",
                "335542039264217065079296989417461294694",
                "296150711073088609084390075015880658975"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105249-2b2396ce",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/meta/txtp_process.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "157031685117792206434395846209534741551",
            "length": 2865
        },
        "id": "CVE-2026-105249-4b0340c2",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/meta/mus_acm.c",
            "function": "parse_mus"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "197275797228318780486615163501610662271",
            "length": 1352
        },
        "id": "CVE-2026-105249-52e3c036",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/meta/txtp_process.c",
            "function": "make_group_random"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "292596885354562570734643441974552222465",
            "length": 1471
        },
        "id": "CVE-2026-105249-69150f8f",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/coding/psx_decoder.c",
            "function": "ps_find_padding"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "126366064877753608228551421847227752391",
                "256358577321216918515040422697826661095",
                "324911952815662409498315996761522187675",
                "229062097149129615251734303790004443621",
                "275491718711092959219307275697209147148",
                "716407587958725348062976086138125789",
                "275781060332014179518435619178840708848",
                "226846371991247407173102133515697672838",
                "279706029882529935789883004001216895768"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105249-8043c0ea",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/coding/psx_decoder.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "65973427816333387397513283991130181863",
            "length": 2114
        },
        "id": "CVE-2026-105249-872c57cb",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/meta/awb.c",
            "function": "init_vgmstream_awb_memory"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "134622419795886457617875045520913668775",
                "214650664164427520112557524052800536473",
                "326437658612950714337511886563505078742",
                "149368706715759937841290787272741104476",
                "154204545848386298322298961008299004146",
                "39882210791512762145354522531301775142",
                "118877436249817330260279694700750649654"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105249-abe1f893",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/meta/awb.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "227726273410518958710269584201445417286",
                "277609735454390599593020302753213892440",
                "201925238093322803516874118978487680824",
                "22797891440466018711134145158821279660",
                "207863274498105027805871801169732714857",
                "129667469129503579639724060674026198838",
                "41039891034359540688242295159842704115",
                "12616511260691492847972094834756637813",
                "285702210237374862010406241132795859283",
                "223326511966914072456640840773346854037",
                "128118525530024257850638119121653739636",
                "144892340657499280682089373220899369243"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-105249-e2bec889",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/vgmstream/vgmstream/commit/ae37662ad626254ddd96ad69ac263792d7a92024",
        "target": {
            "file": "src/meta/mus_acm.c"
        }
    }
]
vanir_signatures_modified
"2026-10-09T07:07:28Z"