Advisories ยป MGASA-2026-0297

Updated vorbis-tools package fixes a security vulnerability

Publication date: 25 Jul 2026
Modification date: 25 Jul 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-34253

Description

The updated package fixes a security vulnerability:
A buffer underflow vulnerability has been identified in the ogg123
utility from the vorbis-tools 1.4.3 package in function remotethread in
remote.c. This vulnerability occurs in the remote control functionality
when processing malformed input, leading to a stack buffer underflow
that can cause application crashes and potentially allow code execution.
(CVE-2026-34253)
                

References

SRPMS

10/core

9/core