CVE-2023-45682: Nothings Stb Vorbis.c
High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger out of bounds read in `DECODE` macro when `var` is negative. As it can be seen in the definition of `DECODE_RAW` a negative `var` is a valid value. This issue may be used to leak internal memory allocation information.
Affected products
- Nothings Stb Vorbis.c: version 1.22 only
Published 2023-10-21. Last modified 2026-06-17.