PatchSiren cyber security CVE debrief
CVE-2026-105251 vgmstream CVE debrief
A vulnerability was detected in vgmstream up to r2117, specifically in the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler, which results in an out-of-bounds read. The attack is possible to be carried out remotely. A patch is available, named 4b8316652a30d40f99ad43310bed273fd1f8a7a3. Defenders should verify exposure, apply the patch, and monitor for exploitation attempts to prevent potential remote exploitation. This vulnerability allows for out-of-bounds reads, which could lead to information disclosure or system crashes. It is crucial for defenders to assess the impact and apply necessary patches.
- Vendor
- vgmstream
- Product
- vgmstream
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for vgmstream installations should assess exposure and apply the patch to prevent potential remote exploitation. They should also review and update vulnerable vgmstream installations, monitor for potential remote exploitation attempts, and verify affected product deployments exist in managed environments. Additionally, defenders should track exceptions, retest remediated assets, and close the item only after evidence is documented.
Why it matters
CVE-2026-105251 is a remotely exploitable vulnerability in vgmstream up to r2117, allowing for out-of-bounds reads. Defenders should verify exposure, apply the patch, and monitor for exploitation attempts.
- Verify and apply patch to prevent remote exploitation
- Assess and update vulnerable vgmstream installations to prevent potential impact
- Monitor for potential remote exploitation attempts to detect possible attacks
Technical summary
The vulnerability is located in the ps_find_padding function of the psx_decoder.c file in the VAG File Handler component of vgmstream up to r2117, leading to an out-of-bounds read. Remote exploitation is possible. The patch named 4b8316652a30d40f99ad43310bed273fd1f8a7a3 is available to address this issue. Defenders should assess exposure and apply the patch to prevent potential remote exploitation. The vulnerability allows for out-of-bounds reads, which could lead to information disclosure or system crashes. It is crucial for defenders to assess the impact and apply necessary patches.
Defensive priority
Apply patch
Recommended defensive actions
- Apply the patch 4b8316652a30d40f99ad43310bed273fd1f8a7a3 to address the issue
- Review and update vulnerable vgmstream installations
- Monitor for potential remote exploitation attempts
- Verify affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD entry provide details about the vulnerability, but the scope of affected versions and potential impact require further verification. The vulnerability is located in the ps_find_padding function of the psx_decoder.c file in the VAG File Handler component of vgmstream up to r2117. The attack is possible to be carried out remotely, and defenders should verify exposure, apply the patch, and monitor for exploitation attempts. The CVE Program record and NVD entry provide source-provided CVE metadata and official NIST
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105251 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105251
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105251 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105251
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/vgmstream/vgmstream/
-
Source reference
Unverified legacy reference
URL: https://github.com/vgmstream/vgmstream/commit/4b8316652a30d40f99ad43310bed273fd1f8a7a3
-
Source reference
Unverified legacy reference
URL: https://github.com/vgmstream/vgmstream/issues/2000
-
Source reference
Unverified legacy reference
URL: https://github.com/vgmstream/vgmstream/pull/2001
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/cve/CVE-2026-105251
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/976281
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413458
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/413458/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.