Ogg Vorbis is a fully open, non-proprietary, patent- and royalty-free,
general-purpose compressed audio format for audio and music at fixed
and variable bitrates from 16 to 128 kbps/channel.
The vorbis package contains an encoder, a decoder, a playback tool, and a
comment editor.
Update Information:
CVE-2026-34253 - fix arbitrary code execution via buffer underflow
* Tue Jun 9 2026 Lukáš Zaoral
[ 1 ] Bug #2479549 - CVE-2026-34253 vorbis-tools: vorbis-tools ogg123: Arbitrary code execution via buffer underflow in remote control functionality [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2479549
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-884a9f0fc3' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.