Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:25198: Important: libsndfile security update

An integer overflow vulnerability (CVE-2026-37555, CVSS 7.5 HIGH) exists in the `ima_reader_init()` function of libsndfile, which could allow for arbitrary code execution or application crashes when processing malicious audio files. The NVD lists libsndfile version 1.2.2 as affected, but the specific fixed version is not provided in the available data. Red Hat has released patched packages for Red Hat Enterprise Linux 8.6 Extended Update Support variants, which should be applied immediately.
Read Full Article →

Red Hat Product Errata RHSA-2026:25198 - Security Advisory Issued: 2026-06-11 Updated: 2026-06-11 RHSA-2026:25198 - Security Advisory Overview Updated Packages Synopsis Important: libsndfile security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for libsndfile is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support and Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description libsndfile is a C library for reading and writing files containing sampled sound, such as AIFF, AU, or WAV. Security Fix(es): libsndfile: integer overflow in ima_reader_init() (CVE-2026-37555) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 x86_64 Red Hat Enterprise Linux Server - AUS 8.6 x86_64 Fixes BZ - 2463856 - CVE-2026-37555 libsndfile: integer overflow in ima_reader_init() CVEs CVE-2026-37555 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.6 SRPM libsndfile-1.0.28-13.el8_6.src.rpm SHA-256: fbd628bd88b4b09cb80cfd23e1712c7381eb654a10aa03e974caa67e9ad6fa70 x86_64 libsndfile-1.0.28-13.el8_6.i686.rpm SHA-256: 3615089abc6950f39fb03b99954b94e0ad1fb3ceb9e9b10744bf05595c943213 libsndfile-1.0.28-13.el8_6.x86_64.rpm SHA-256: 07f2d6fe819b64d09a82ee4bd373e2fa9b51bbec3c7d2de4726f161002af2b4e libsndfile-debuginfo-1.0.28-13.el8_6.i686.rpm SHA-256: 0df234cc9d99fb8f59031db9c96bafbd7c50b1fc664cf4ffa02439249371656c libsndfile-debuginfo-1.0.28-13.el8_6.x86_64.rpm SHA-256: 96c6c235bae3402d7ee6e05fcf65b077fa565f4ab59efc681dae8fcbfd5def82 libsndfile-debugsource-1.0.28-13.el8_6.i686.rpm SHA-256: fc11de4e710f692f2b1e4d52f3a86d06da50c86f437ac4a5f0fb1692c5934454 libsndfile-debugsource-1.0.28-13.el8_6.x86_64.rpm SHA-256: 679213ff82537c0c8ace83552862bf4078ca090d706601138a2493c086ea9473 libsndfile-utils-debuginfo-1.0.28-13.el8_6.i686.rpm SHA-256: dda601c6eb615e033f80766b9951c51de82673b4375ecacb9a70ef8a1e81ddb5 libsndfile-utils-debuginfo-1.0.28-13.el8_6.x86_64.rpm SHA-256: 04d0c889748986f0a40e2e6436fcfaab77631770d2984fe488a3579fec740d13 Red Hat Enterprise Linux Server - AUS 8.6 SRPM libsndfile-1.0.28-13.el8_6.src.rpm SHA-256: fbd628bd88b4b09cb80cfd23e1712c7381eb654a10aa03e974caa67e9ad6fa70 x86_64 libsndfile-1.0.28-13.el8_6.i686.rpm SHA-256: 3615089abc6950f39fb03b99954b94e0ad1fb3ceb9e9b10744bf05595c943213 libsndfile-1.0.28-13.el8_6.x86_64.rpm SHA-256: 07f2d6fe819b64d09a82ee4bd373e2fa9b51bbec3c7d2de4726f161002af2b4e libsndfile-debuginfo-1.0.28-13.el8_6.i686.rpm SHA-256: 0df234cc9d99fb8f59031db9c96bafbd7c50b1fc664cf4ffa02439249371656c libsndfile-debuginfo-1.0.28-13.el8_6.x86_64.rpm SHA-256: 96c6c235bae3402d7ee6e05fcf65b077fa565f4ab59efc681dae8fcbfd5def82 libsndfile-debugsource-1.0.28-13.el8_6.i686.rpm SHA-256: fc11de4e710f692f2b1e4d52f3a86d06da50c86f437ac4a5f0fb1692c5934454 libsndfile-debugsource-1.0.28-13.el8_6.x86_64.rpm SHA-256: 679213ff82537c0c8ace83552862bf4078ca090d706601138a2493c086ea9473 libsndfile-utils-debuginfo-1.0.28-13.el8_6.i686.rpm SHA-256: dda601c6eb615e033f80766b9951c51de82673b4375ecacb9a70ef8a1e81ddb5 libsndfile-utils-debuginfo-1.0.28-13.el8_6.x86_64.rpm SHA-256: 04d0c889748986f0a40e2e6436fcfaab77631770d2984fe488a3579fec740d13 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article