CVE-2026-105251
Medium severity, CVSS 6.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability was detected in vgmstream up to r2117. Affected by this vulnerability is the function ps_find_padding of the file src/coding/psx_decoder.c of the component VAG File Handler. Performing a manipulation results in out-of-bounds read. The attack is possible to be carried out remotely. The patch is named 4b8316652a30d40f99ad43310bed273fd1f8a7a3. It is suggested to install a patch to address this issue.
Published 2026-10-05. Last modified 2026-10-06.