Red Hat Product Errata RHSA-2026:23222 - Security Advisory Issued: 2026-06-04 Updated: 2026-06-04 RHSA-2026:23222 - Security Advisory Overview Updated Packages Synopsis Important: libsndfile security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libsndfile is now available for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description libsndfile is a C library for reading and writing files containing sampled sound, such as AIFF, AU, or WAV. Security Fix(es): libsndfile: integer overflow in ima_reader_init() (CVE-2026-37555) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.4 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.4 s390x Fixes BZ - 2463856 - CVE-2026-37555 libsndfile: integer overflow in ima_reader_init() CVEs CVE-2026-37555 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.4 SRPM libsndfile-1.0.31-8.el9_4.2.src.rpm SHA-256: 970e0959f71060e6d956971c501ec25a962045425c5c85c0d9d0914d1f858fc7 x86_64 libsndfile-1.0.31-8.el9_4.2.i686.rpm SHA-256: 72bb575c2ba3b8a9b75958608e6748daba54d11956d18697475a64f31db2ab41 libsndfile-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: bcdcd3899d40c2d2905abe8f37104abf41e3f3fa742aadc1f64e0e3780b438ef libsndfile-debuginfo-1.0.31-8.el9_4.2.i686.rpm SHA-256: 32f2ac5b30600c745daae74c511bc1e8b60a0368222bb460702ff3f286694ecf libsndfile-debuginfo-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: a70d1dc6cd29ff684917e67841759b592140601e452e9f879d0667ce788836dd libsndfile-debugsource-1.0.31-8.el9_4.2.i686.rpm SHA-256: d2ab88908b83063da1aaa3dde77edd252d299fcc8c279b9d6d3a0882fde297d9 libsndfile-debugsource-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: bbb0007d7fe9c9c3c8e2eda96d3e7001077d3708ab3be9dbabc280504cd5a222 libsndfile-utils-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: c3b235e81f4463fafd6dc335a5a07ba941f856cedd65e486b5d2ea1e7b460f51 libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.i686.rpm SHA-256: b6c63a80bb22dc80ee006ee04092173b3c37357566b6a81286bdeaa426bd0acf libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: 2159bf4860ef028bf1bedd197c1787364e292bb79c8dbbf152e1cacbda46525c Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.4 SRPM libsndfile-1.0.31-8.el9_4.2.src.rpm SHA-256: 970e0959f71060e6d956971c501ec25a962045425c5c85c0d9d0914d1f858fc7 ppc64le libsndfile-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: 1ef1a4245589a52e73608a801779ad6512b79b9fc341601fa5e36b224cf425b6 libsndfile-debuginfo-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: d38784bfb330e9be4563850985914aa91e2105a74a91783c7e16bd0bfa1e5e37 libsndfile-debugsource-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: 519770c461222a549963bae688c0fae6c3076963cc826adfb2b856910f896e14 libsndfile-utils-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: ff144e3169ba6d79184a2bd69916ea186938f755a6b05e279962135ab275a9fe libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: f3253f5bcc4be8a01bfda84f95b2b80a9bc389ae1ed23f86c00377af9a6619df Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.4 SRPM libsndfile-1.0.31-8.el9_4.2.src.rpm SHA-256: 970e0959f71060e6d956971c501ec25a962045425c5c85c0d9d0914d1f858fc7 x86_64 libsndfile-1.0.31-8.el9_4.2.i686.rpm SHA-256: 72bb575c2ba3b8a9b75958608e6748daba54d11956d18697475a64f31db2ab41 libsndfile-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: bcdcd3899d40c2d2905abe8f37104abf41e3f3fa742aadc1f64e0e3780b438ef libsndfile-debuginfo-1.0.31-8.el9_4.2.i686.rpm SHA-256: 32f2ac5b30600c745daae74c511bc1e8b60a0368222bb460702ff3f286694ecf libsndfile-debuginfo-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: a70d1dc6cd29ff684917e67841759b592140601e452e9f879d0667ce788836dd libsndfile-debugsource-1.0.31-8.el9_4.2.i686.rpm SHA-256: d2ab88908b83063da1aaa3dde77edd252d299fcc8c279b9d6d3a0882fde297d9 libsndfile-debugsource-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: bbb0007d7fe9c9c3c8e2eda96d3e7001077d3708ab3be9dbabc280504cd5a222 libsndfile-utils-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: c3b235e81f4463fafd6dc335a5a07ba941f856cedd65e486b5d2ea1e7b460f51 libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.i686.rpm SHA-256: b6c63a80bb22dc80ee006ee04092173b3c37357566b6a81286bdeaa426bd0acf libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: 2159bf4860ef028bf1bedd197c1787364e292bb79c8dbbf152e1cacbda46525c Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.4 SRPM libsndfile-1.0.31-8.el9_4.2.src.rpm SHA-256: 970e0959f71060e6d956971c501ec25a962045425c5c85c0d9d0914d1f858fc7 aarch64 libsndfile-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: 00c9ca170da27ae07c90481b431f01d3fdfc5b99d1fb3ae809dd9e129f8bf784 libsndfile-debuginfo-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: 3bf29dd26c06aaed8e6272b50a2cb5373e3f90e7deb1ebaa7a688e76fe7cebf5 libsndfile-debugsource-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: 8546928135867f3fce6345314d1caa014a062e4ff164941aec030f263a9c5e14 libsndfile-utils-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: e8c2357901a881d234f420dc267ed6ba88e8cac2ecc71c5ae3a0e7564d03aaae libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: bce6bbe7bd7df2f9a960c2b1302caacd1ed0d6bb732b44f97785e7c165aceba7 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.4 SRPM libsndfile-1.0.31-8.el9_4.2.src.rpm SHA-256: 970e0959f71060e6d956971c501ec25a962045425c5c85c0d9d0914d1f858fc7 s390x libsndfile-1.0.31-8.el9_4.2.s390x.rpm SHA-256: 7c9ea9b6c444d648e2e44faae2eba05f37fb47bf3e63f98d7c9b5fbf26b463c8 libsndfile-debuginfo-1.0.31-8.el9_4.2.s390x.rpm SHA-256: 3cc0ee01365e4cc83e18356858d6edd3b71a599bc4f616a0f950ca91d5defe62 libsndfile-debugsource-1.0.31-8.el9_4.2.s390x.rpm SHA-256: eabd56e386d00fb495963841d5d1629690b4e4e7f7049652ca2841b68b998c16 libsndfile-utils-1.0.31-8.el9_4.2.s390x.rpm SHA-256: 7712ff5fd79fe0418a34af5283648a2bca36130eedd0245b8038da77f259bc0a libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.s390x.rpm SHA-256: a7bbd41474582dfe6120389914ba4f75d247ae1ff35e3cad12bf0665e512ec31 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.4 SRPM libsndfile-1.0.31-8.el9_4.2.src.rpm SHA-256: 970e0959f71060e6d956971c501ec25a962045425c5c85c0d9d0914d1f858fc7 x86_64 libsndfile-1.0.31-8.el9_4.2.i686.rpm SHA-256: 72bb575c2ba3b8a9b75958608e6748daba54d11956d18697475a64f31db2ab41 libsndfile-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: bcdcd3899d40c2d2905abe8f37104abf41e3f3fa742aadc1f64e0e3780b438ef libsndfile-debuginfo-1.0.31-8.el9_4.2.i686.rpm SHA-256: 32f2ac5b30600c745daae74c511bc1e8b60a0368222bb460702ff3f286694ecf libsndfile-debuginfo-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: a70d1dc6cd29ff684917e67841759b592140601e452e9f879d0667ce788836dd libsndfile-debugsource-1.0.31-8.el9_4.2.i686.rpm SHA-256: d2ab88908b83063da1aaa3dde77edd252d299fcc8c279b9d6d3a0882fde297d9 libsndfile-debugsource-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: bbb0007d7fe9c9c3c8e2eda96d3e7001077d3708ab3be9dbabc280504cd5a222 libsndfile-utils-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: c3b235e81f4463fafd6dc335a5a07ba941f856cedd65e486b5d2ea1e7b460f51 libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.i686.rpm SHA-256: b6c63a80bb22dc80ee006ee04092173b3c37357566b6a81286bdeaa426bd0acf libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.x86_64.rpm SHA-256: 2159bf4860ef028bf1bedd197c1787364e292bb79c8dbbf152e1cacbda46525c Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.4 SRPM libsndfile-1.0.31-8.el9_4.2.src.rpm SHA-256: 970e0959f71060e6d956971c501ec25a962045425c5c85c0d9d0914d1f858fc7 aarch64 libsndfile-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: 00c9ca170da27ae07c90481b431f01d3fdfc5b99d1fb3ae809dd9e129f8bf784 libsndfile-debuginfo-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: 3bf29dd26c06aaed8e6272b50a2cb5373e3f90e7deb1ebaa7a688e76fe7cebf5 libsndfile-debugsource-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: 8546928135867f3fce6345314d1caa014a062e4ff164941aec030f263a9c5e14 libsndfile-utils-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: e8c2357901a881d234f420dc267ed6ba88e8cac2ecc71c5ae3a0e7564d03aaae libsndfile-utils-debuginfo-1.0.31-8.el9_4.2.aarch64.rpm SHA-256: bce6bbe7bd7df2f9a960c2b1302caacd1ed0d6bb732b44f97785e7c165aceba7 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.4 SRPM libsndfile-1.0.31-8.el9_4.2.src.rpm SHA-256: 970e0959f71060e6d956971c501ec25a962045425c5c85c0d9d0914d1f858fc7 ppc64le libsndfile-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: 1ef1a4245589a52e73608a801779ad6512b79b9fc341601fa5e36b224cf425b6 libsndfile-debuginfo-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: d38784bfb330e9be4563850985914aa91e2105a74a91783c7e16bd0bfa1e5e37 libsndfile-debugsource-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: 519770c461222a549963bae688c0fae6c3076963cc826adfb2b856910f896e14 libsndfile-utils-1.0.31-8.el9_4.2.ppc64le.rpm SHA-256: ff144e3169ba6d79184a2bd69916ea186938f755a6b05e279962135ab275a9fe libsndfile-uti
An integer overflow vulnerability (CVE-2026-37555, CVSS 7.5 HIGH) exists in the `ima_reader_init()` function of libsndfile, a library for reading and writing audio files. The affected version is libsndfile 1.2.2. Red Hat has released a security update for Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions, with the fixed package being libsndfile version 1.0.31-8.el9_4.2.