NIXPKGS-2026-2542
GitHub issue
published 3 hours ago
vgmstream txth-txtp txth.c sscanf stack-based overflow
Permalink
CVE-2026-86514
2.1 LOW
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): Passive (P)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): Low (L)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Exploit Maturity (E): POC (P)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Passive (P)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): Low (L)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
by @LeSuisse Activity log
- Created suggestion
- @LeSuisse ignored package deadbeefPlugins.vgmstream
- @LeSuisse accepted
- @LeSuisse published on GitHub
vgmstream txth-txtp txth.c sscanf stack-based overflow
A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. Patch name: 4669d37a6af94866f6f0628678f9f90d46954e8b. To fix this issue, it is recommended to deploy a patch.
References
-
-
-
CVE-2026-86514 | CVE Analysis and Report third-party-advisory
-
Submit #908369 | vgmstream r2117 Stack-based Buffer Overflow third-party-advisory
-
-
Affected products
vgmstream
- ==r2117
Matching in nixpkgs
Ignored packages (1)
pkgs.deadbeefPlugins.vgmstream
Streaming video game music decoder plugin for the DeaDBeeF music player
-
nixos-unstable 2026-06-22
- nixpkgs-unstable 2026-06-22
- nixos-unstable-small 2026-06-22
-
nixos-26.05 2026-05-09.1
- nixos-26.05-small 2026-05-09.1
- nixpkgs-26.05-darwin 2026-05-09.1
Package maintainers
-
@vs49688 Zane van Iperen <zane@zanevaniperen.com>