Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Mageia 9 Libxmp Important Free Pointer Memory Issues MGASA-2026-0191

mageia
Calendar Grey June 10, 2026
Dist Mageia Esm H88
Security update for Mageia 9 addressing multiple critical memory issues and potential exploits.
Security update

Summary

Description: CVE-2023-45679: Attempt to free an uninitialized memory pointer in vorbis_deinit() CVE-2023-45680: Null pointer dereference in vorbis_deinit() CVE-2023-45681: Out of bounds heap buffer write CVE-2023-45676: Multi-byte write heap buffer overflow in start_decoder() CVE-2023-45677: Heap buffer out of bounds write in start_decoder() CVE-2023-45682: Wild address read in vorbis_decode_packet_rest() CVE-2025-47256 stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.

References

- https://bugs.mageia.org/show_bug.cgi?id=33915

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CVZWMTH36ES7RCJEMRANBDTL76QBE75Z/

- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FKMOFYKVMD2LPU7O33SEH2RGSY2ZE73K/

- https://www.cve.org/CVERecord?id=CVE-2023-45676

- https://www.cve.org/CVERecord?id=CVE-2023-45677

- https://www.cve.org/CVERecord?id=CVE-2023-45679

- https://www.cve.org/CVERecord?id=CVE-2023-45680

- https://www.cve.org/CVERecord?id=CVE-2023-45681

- https://www.cve.org/CVERecord?id=CVE-2023-45682

- https://www.cve.org/CVERecord?id=CVE-2025-47256

Resolution

SRPMS

- 9/core/libxmp-4.5.0-2.1.mga9

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 10 Jun 2026 
URL: https://advisories.mageia.org/MGASA-2026-0191.html
Type: security
CVE: CVE-2023-45676, CVE-2023-45677, CVE-2023-45679, CVE-2023-45680, CVE-2023-45681, CVE-2023-45682, CVE-2025-47256

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here