Bug 2454516
| Summary: | CVE-2026-5316 stb: invalid free when processing a crafted ogg vorbis file [fedora-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora | Reporter: | Guilherme de Almeida Suckevicz <gsuckevi> |
| Component: | stb | Assignee: | Ben Beasley <code> |
| Status: | ASSIGNED --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | rawhide | CC: | code, mhroncok |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["de488118-e92e-472e-9dd5-71a001a4bc7a"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2454178 | ||
|
Description
Guilherme de Almeida Suckevicz
2026-04-02 18:22:17 UTC
https://www.cve.org/CVERecord?id=CVE-2026-5316 Since this has not been triaged or fixed upstream, and no suggested patch was published, there’s nothing to be done at this time. I’m not planning to try to evaluate the validity of the CVE and devise a downstream patch myself. If a suggested patch appears, I’m happy to evaluate it ahead of upstream if necessary. |