CVE-2026-86514 Details
Description
A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.
A stack-based buffer overflow vulnerability has been identified in vgmstream versions through r2117. The issue arises in the TXTH and TXTP text parsers, where unbounded input handling by sscanf allows for overwriting of stack memory. This vulnerability can be exploited remotely, potentially leading to application crashes and code execution in software that embeds vgmstream.
Users are advised to update to the latest version of vgmstream, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/vgmstream/vgmstream/ | [email protected] | Vendor |
| https://github.com/vgmstream/vgmstream/commit/4669d37a6af94866f6f0628678f9f90d46954e8b | [email protected] | Source CodeVendor |
| https://github.com/vgmstream/vgmstream/issues/1972 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/vgmstream/vgmstream/pull/1956 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-86514 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/908369 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399668 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/399668/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-121 | Stack-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vgmstream | r2117 |
CPE
Remediation
| |
| vgmstream-cli | All versions |
CPE
Remediation
| |
| vgmstream123 | All versions |
CPE
Remediation
| |
| vgmstream.so | All versions |
CPE
Remediation
| |
| foo_input_vgmstream | All versions |
CPE
Remediation
| |
| in_vgmstream | All versions |
CPE
Remediation
| |
| xmp-vgmstream | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 11, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion