Executive brief
vgmstream is a library used to playback audio formats from video games. An attacker can craft a malicious txtp (playlist-like) file that manipulates the range_start and range_end arguments to consume excessive system resources, potentially causing a denial of service.
Technical details
The vulnerability exists in the add_entry function of src/meta/txtp_parser.c in vgmstream up to revision r2117. Improper validation of the range_start and range_end arguments allows an attacker to trigger uncontrolled resource consumption. The attack vector is remote—a victim can be exploited by opening a malicious .txtp file. The vulnerability has been publicly disclosed and a patch is available (commit 4b6a02dd1aff6428255db912563d77d4cb0a143e). No authentication or special privileges are required to trigger the issue.
Affected products
- vgmstream vgmstream up to r2117
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Patch commit 4b6a02dd1aff6428255db912563d77d4cb0a143e