CVE-2026-105249EPSS p1.0%
CVE-2026-105249CVE-2026-105249
Description
A weakness has been identified in vgmstream up to r2117. This impacts the function make_group_random of the file src/meta/txtp_process.c of the component TXTP File Handler. This manipulation causes use after free. The attack needs to be launched locally. Patch name: ae37662ad626254ddd96ad69ac263792d7a92024. It is recommended to apply a patch to fix this issue.
Scoring
| CVSS | 4.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
| EPSS | 0.10% probability of exploitation · percentile 1.0% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |