PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105251 vgmstream CVE debrief

A vulnerability was detected in vgmstream up to r2117, specifically in the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler, which results in an out-of-bounds read. The attack is possible to be carried out remotely. A patch is available, named 4b8316652a30d40f99ad43310bed273fd1f8a7a3. Defenders should verify exposure, apply the patch, and monitor for exploitation attempts to prevent potential remote exploitation. This vulnerability allows for out-of-bounds reads, which could lead to information disclosure or system crashes. It is crucial for defenders to assess the impact and apply necessary patches.

Vendor
vgmstream
Product
vgmstream
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for vgmstream installations should assess exposure and apply the patch to prevent potential remote exploitation. They should also review and update vulnerable vgmstream installations, monitor for potential remote exploitation attempts, and verify affected product deployments exist in managed environments. Additionally, defenders should track exceptions, retest remediated assets, and close the item only after evidence is documented.

Why it matters

CVE-2026-105251 is a remotely exploitable vulnerability in vgmstream up to r2117, allowing for out-of-bounds reads. Defenders should verify exposure, apply the patch, and monitor for exploitation attempts.

  • Verify and apply patch to prevent remote exploitation
  • Assess and update vulnerable vgmstream installations to prevent potential impact
  • Monitor for potential remote exploitation attempts to detect possible attacks

Technical summary

The vulnerability is located in the ps_find_padding function of the psx_decoder.c file in the VAG File Handler component of vgmstream up to r2117, leading to an out-of-bounds read. Remote exploitation is possible. The patch named 4b8316652a30d40f99ad43310bed273fd1f8a7a3 is available to address this issue. Defenders should assess exposure and apply the patch to prevent potential remote exploitation. The vulnerability allows for out-of-bounds reads, which could lead to information disclosure or system crashes. It is crucial for defenders to assess the impact and apply necessary patches.

Defensive priority

Apply patch

Recommended defensive actions

  • Apply the patch 4b8316652a30d40f99ad43310bed273fd1f8a7a3 to address the issue
  • Review and update vulnerable vgmstream installations
  • Monitor for potential remote exploitation attempts
  • Verify affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD entry provide details about the vulnerability, but the scope of affected versions and potential impact require further verification. The vulnerability is located in the ps_find_padding function of the psx_decoder.c file in the VAG File Handler component of vgmstream up to r2117. The attack is possible to be carried out remotely, and defenders should verify exposure, apply the patch, and monitor for exploitation attempts. The CVE Program record and NVD entry provide source-provided CVE metadata and official NIST

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105251 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105251

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105251 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105251

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.