A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-119",
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86514.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86514.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "210937905086117524333018005236676132712",
"length": 1210
},
"id": "CVE-2026-86514-299a389c",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/txth.c",
"function": "parse_txth"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "240947816876739371289925959388822149590",
"length": 736
},
"id": "CVE-2026-86514-6f12cd33",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/txth.c",
"function": "read_name_table_keyval"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"2122129323639591140243535359035707748",
"175992924504119307059030725896451705189",
"8578730983801804564699158458186231237",
"184857129169371901802025453949648156277",
"270747881240990065819951449076195211377",
"99236865218969821742788592919650544294",
"28713654712348825120917018297209597521",
"279706045409308703792350211829012871363",
"335625305700062644265660060908022161116",
"93493598223335004098986033828027510602",
"66973440809030112087453730938238365683",
"180501355133681983305316587889852055518",
"10260482236162315496078403461986602772",
"313348357705237436321816622066920470633",
"80617028483414671040701986239923491445",
"255714393894347493734328499172311701419",
"235290988048088328919377416280797818259",
"286043587406462977680357936331791620093",
"149768115648346780949367937962912445188"
],
"threshold": 0.9
},
"id": "CVE-2026-86514-7d0bfb03",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/vab.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "313552854564464827963708105390596399446",
"length": 8053
},
"id": "CVE-2026-86514-83e3f6ef",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/txtp_parser.c",
"function": "parse_params"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "169869113893165772399438610755534419452",
"length": 1179
},
"id": "CVE-2026-86514-8672f6e7",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/util/companion_files.c",
"function": "read_filemap_file_pos"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"123504500487074886835908868846128954502",
"325660362459751401148099950955046028552",
"208869519917449446471960362574825750274",
"208384399766797710145387466902318145896",
"170479300308442492202848769066052579204",
"231060525351606209307233201545649211301",
"94428904614677909886528837483579421348",
"85292847858433837593193243833958225573",
"326256219273164275546491933839170697184",
"72476881702256180644871334802740332291",
"71075372559608234932158515466776340538",
"272462153525953438595143905609880620900",
"115349696944838020572902536927718839897",
"195219500055242630245815207669540644754",
"183620355807774866294726186937862757436",
"50666533942764631143788714696146443403",
"277000987778008354768869703608025988976",
"141555032971677449256421462118361865515",
"291831188251415993397566886541947526690",
"232672025539806069511359550312587809619",
"147097090217565029740770619858245156255",
"259980375110605340060119723174024866604",
"275021183996208428553142025922847764233",
"265369295078492587736735238022254937512",
"289284478848262508178023973799981208684",
"46049847690024521383443879526580704784",
"139326260338836970777345271454045153736",
"150763245776641485531339834532564017922",
"331521691510353673718732384658273032441",
"35494242537824720029831654055157640646",
"166672656682198016101765692982236084165",
"20749963902393409676271609306304372330",
"20067816504551869368959614292340688909",
"219089626582004729547564123746943396385",
"169941782556431014139573436436882115995",
"66764864528864610651104752766571852442",
"217302874360757585136149774746532685095",
"119785955019368837787187192545935823835",
"219634137059624438135184311551828975512"
],
"threshold": 0.9
},
"id": "CVE-2026-86514-b47b2e5e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/txth.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "6251215245236353607848844459300233645",
"length": 1507
},
"id": "CVE-2026-86514-b4cac3e9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/txth.c",
"function": "parse_name_table"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "6529522278535992722596009396707913223",
"length": 1286
},
"id": "CVE-2026-86514-d30edfff",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/vab.c",
"function": "read_vabcfg_file"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"168348206668821685216649600698195382393",
"183193443818406998822358812974108444874",
"158793720762519132353135991183662146942",
"34546730212578083898217647145936726419",
"295408909672985459716689154263483794553",
"99236865218969821742788592919650544294",
"176326550420574243284558467982731607730",
"94058947040592871021923146133676807033",
"284327336247734022692153190524903742846",
"277975503351058196071225464015444054039",
"187527202138785114072207721493235568683",
"61595036742802441543448723759558531903",
"46824034405447686112273281533420753513",
"327062071992681142733205589110546850630",
"268461899201353036297018322415713359214"
],
"threshold": 0.9
},
"id": "CVE-2026-86514-e7553d8f",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/util/companion_files.c"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"290526940792817135678485191427675882984",
"52677055213520356455494298710707035521",
"50184689649637776034998106828235770442",
"196880909990854324521800665186183269942",
"233860039182357703013044418585708504098",
"255677395111786941629883558438777346623",
"6712995117269568816141743315308676748",
"14501210978915609160567836835744497722",
"109605000079008375448386602996374697275",
"305000720499753877644730428957674545501",
"186076347112666814386830146744315396828",
"3512415185316860533955792589022261442",
"304847017695471671323454081318546911476",
"171890448967090225983128107086365645446",
"232093731644783974065133611126840180746"
],
"threshold": 0.9
},
"id": "CVE-2026-86514-eb5e536b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/txtp_parser.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "123061721046733497480769399278193996127",
"length": 739
},
"id": "CVE-2026-86514-ed81e730",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/txth.c",
"function": "parse_multi_txth"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "324931028985457746053547013806261434322",
"length": 1142
},
"id": "CVE-2026-86514-fa59c667",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b",
"target": {
"file": "src/meta/txtp_parser.c",
"function": "txtp_parse"
}
}
]
"2026-09-12T14:00:56Z"