Updated vorbis-tools package fixes a security vulnerability
Publication date: 25 Jul 2026Modification date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-34253
Description
The updated package fixes a security vulnerability:
A buffer underflow vulnerability has been identified in the ogg123
utility from the vorbis-tools 1.4.3 package in function remotethread in
remote.c. This vulnerability occurs in the remote control functionality
when processing malformed input, leading to a stack buffer underflow
that can cause application crashes and potentially allow code execution.
(CVE-2026-34253)
References
- https://bugs.mageia.org/show_bug.cgi?id=35627
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/QQDC2BQN5WTT7MV425PV3C4SL4HR3JD4/
- https://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FQREVQVTSI5B3ALQBRUPJMWUOU724VOS/
- https://www.cve.org/CVERecord?id=CVE-2026-34253
SRPMS
10/core
- vorbis-tools-1.4.3-2.1.mga10
9/core
- vorbis-tools-1.4.2-3.2.mga9