Null pointer dereference in vorbis_deinit in stb_vorbis
CVE-2023-45680
5.3MEDIUM
What is CVE-2023-45680?
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in start_decoder. In that case the function returns early, the f->comment_list is set to NULL, but f->comment_list_length is not reset. Later in vorbis_deinit it tries to dereference the NULL pointer. This issue may lead to denial of service.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
stb <= 1.22
