Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:25197: Important: libsndfile security update

An integer overflow vulnerability (CVE-2026-37555, CVSS 7.5 HIGH) in the libsndfile library's `ima_reader_init()` function can be exploited via specially crafted audio files. The vulnerability affects libsndfile version 1.2.2, as confirmed by the NVD. Red Hat has released patched packages for its supported Enterprise Linux 8.4 streams; specific fixed upstream version information for the libsndfile project is not provided in the available data.
Read Full Article →

Red Hat Product Errata RHSA-2026:25197 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25197 - Security Advisory Overview Updated Packages Synopsis Important: libsndfile security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libsndfile is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description libsndfile is a C library for reading and writing files containing sampled sound, such as AIFF, AU, or WAV. Security Fix(es): libsndfile: integer overflow in ima_reader_init() (CVE-2026-37555) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 x86_64 Red Hat Enterprise Linux Server - AUS 8.4 x86_64 Fixes BZ - 2463856 - CVE-2026-37555 libsndfile: integer overflow in ima_reader_init() CVEs CVE-2026-37555 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.4 SRPM libsndfile-1.0.28-10.el8_4.2.src.rpm SHA-256: b4ec20008f0824bdb85db5cb8891045748a510f4ef0a0f58edbfa30365db0b38 x86_64 libsndfile-1.0.28-10.el8_4.2.i686.rpm SHA-256: 320891d957c6013651a35fa18fb1945cfcab20390ec3c3c9fed95137683ed90f libsndfile-1.0.28-10.el8_4.2.x86_64.rpm SHA-256: faefd6fee3cff2f1833393526d184bfe6e7a36ae9dab7d986283d69f76233592 libsndfile-debuginfo-1.0.28-10.el8_4.2.i686.rpm SHA-256: 22944c022d48d9e72ed25adf53f6370a1d585b3ef4d05039e7a249e71b79d86e libsndfile-debuginfo-1.0.28-10.el8_4.2.x86_64.rpm SHA-256: 695ffdc9eb5e3f8b9df788802d90d3a52e139d1e12fdebfbb0f7ad8a1f5003d1 libsndfile-debugsource-1.0.28-10.el8_4.2.i686.rpm SHA-256: bc2d32f4f597dd1ff3410134fe59fa7901aaf049fd86caa26ff5ea61d38a57df libsndfile-debugsource-1.0.28-10.el8_4.2.x86_64.rpm SHA-256: b607320ccdb27b67061f65117ce0f9bffdfbe25142228f183ca5973d0f0093ac libsndfile-utils-debuginfo-1.0.28-10.el8_4.2.i686.rpm SHA-256: d1980d59e4aa7a446d6da2ff518d0d53661d521475bad25e0a022dbacbe2c3d8 libsndfile-utils-debuginfo-1.0.28-10.el8_4.2.x86_64.rpm SHA-256: 764170874f603ba64572ea4feafd2e4423454ccb272ec8c286a007e166cd42a0 Red Hat Enterprise Linux Server - AUS 8.4 SRPM libsndfile-1.0.28-10.el8_4.2.src.rpm SHA-256: b4ec20008f0824bdb85db5cb8891045748a510f4ef0a0f58edbfa30365db0b38 x86_64 libsndfile-1.0.28-10.el8_4.2.i686.rpm SHA-256: 320891d957c6013651a35fa18fb1945cfcab20390ec3c3c9fed95137683ed90f libsndfile-1.0.28-10.el8_4.2.x86_64.rpm SHA-256: faefd6fee3cff2f1833393526d184bfe6e7a36ae9dab7d986283d69f76233592 libsndfile-debuginfo-1.0.28-10.el8_4.2.i686.rpm SHA-256: 22944c022d48d9e72ed25adf53f6370a1d585b3ef4d05039e7a249e71b79d86e libsndfile-debuginfo-1.0.28-10.el8_4.2.x86_64.rpm SHA-256: 695ffdc9eb5e3f8b9df788802d90d3a52e139d1e12fdebfbb0f7ad8a1f5003d1 libsndfile-debugsource-1.0.28-10.el8_4.2.i686.rpm SHA-256: bc2d32f4f597dd1ff3410134fe59fa7901aaf049fd86caa26ff5ea61d38a57df libsndfile-debugsource-1.0.28-10.el8_4.2.x86_64.rpm SHA-256: b607320ccdb27b67061f65117ce0f9bffdfbe25142228f183ca5973d0f0093ac libsndfile-utils-debuginfo-1.0.28-10.el8_4.2.i686.rpm SHA-256: d1980d59e4aa7a446d6da2ff518d0d53661d521475bad25e0a022dbacbe2c3d8 libsndfile-utils-debuginfo-1.0.28-10.el8_4.2.x86_64.rpm SHA-256: 764170874f603ba64572ea4feafd2e4423454ccb272ec8c286a007e166cd42a0 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article