Junglewise Threat Intelligence

CVE-2026-34253: Xiph.Org vorbis-tools stack buffer underflow in ogg123 remotethread

CVE-2026-34253 · Severity: high · CVSS 8.2 · Published 2026-05-15

Executive brief

A vulnerability was found in ogg123, a command-line audio player for Ogg Vorbis files. The flaw exists in the tool's remote control interface, which allows the player to be managed by other programs or scripts. An attacker could provide specially crafted input to crash the application or potentially take control of the system running the software.

Technical details

A stack buffer underflow exists in the 'remotethread' function within 'remote.c' of the ogg123 utility. The vulnerability is caused by unsafe string manipulation where the code attempts to null-terminate a newline character using 'buf[strlen(buf)-1]=0' without verifying the string length. If an attacker provides an empty string or input starting with a null byte, 'strlen' returns zero, leading to an out-of-bounds write at 'buf[-1]'. This can result in stack corruption, leading to a crash (DoS) or potential remote code execution if the environment allows for control over the remote input stream.

Affected products

  • Xiph.Org Foundation vorbis-tools 1.4.3

Timeline

  • 2026-05-15: disclosed: Vulnerability reported via Xiph.Org GitLab and NVD
  • 2026-05-15: advisory

References