Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue. | |
| Title | vgmstream TXTP File txtp_process.c make_group_random use after free | |
| First Time appeared |
Vgmstream
Vgmstream vgmstream |
|
| Weaknesses | CWE-119 CWE-416 |
|
| CPEs | cpe:2.3:a:vgmstream:vgmstream:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vgmstream
Vgmstream vgmstream |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-10-07T20:44:42.563Z
Reserved: 2026-10-04T17:37:11.048Z
Link: CVE-2026-105249
Updated: 2026-10-07T20:44:38.043Z
Status : Deferred
Published: 2026-10-05T08:17:15.417
Modified: 2026-10-07T21:17:10.733
Link: CVE-2026-105249
No data.
OpenCVE Enrichment
Updated: 2026-10-05T10:00:16Z