CVE-2026-34253 Details
Description
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control functionality when processing malformed input, leading to a stack buffer underflow that can cause application crashes and potentially allow code execution.
A buffer underflow vulnerability has been identified in the ogg123 utility of the Vorbis Tools package version 1.4.3. The issue arises in the remote control functionality, specifically within the 'remotethread' function of 'remote.c'. When the application processes malformed input, it leads to a stack buffer underflow, which can cause the application to crash and potentially allow for arbitrary code execution.
Users can update to Vorbis Tools version 1.4.3 or apply a patch that checks the input buffer's length before processing. This patch is available as a merge request in the Vorbis Tools GitLab repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 15, 2026CISA-ADP
Assessed May 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-34253 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2477925 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-34253.json | redhat-SADP | |
| https://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332 | CISA-ADP | ExploitTechnical DescriptionVendor |
| https://github.com/xiph/vorbis-tools/archive/refs/tags/v1.4.3.tar.gz | [email protected] | Broken LinkSource CodeVendor |
| https://github.com/xiph/vorbis-tools/blob/0b3fbf42eb3897d32f4a75baa2dc915a4ca45e8e/ogg123/remote.c#L153 | [email protected] | Source CodeVendor |
| https://gitlab.xiph.org/xiph/vorbis-tools/-/work_items/2332 | [email protected] | ExploitTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-124 | Buffer Underwrite ('Buffer Underflow') | redhat-SADP |
| CWE-124 | Buffer Underwrite ('Buffer Underflow') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Xiph.Org Vorbis-tools | 1.4.3 (semver) |
CPE
Remediation
| |
| Xiph.Org Vorbis-tools ogg123 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | CVE Modified | CISA-ADP |
| May 15, 2026 | New CVE Received | [email protected] |
Volerion