Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 528
Alerts This Week
Warning Icon 1 528

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found 98 articles for you...
217

Oracle Linux 10 ELSA-2026-19560 libsndfile Important Fix CVE-2026-37555

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19560 http://linux.oracle.com/errata/ELSA-2026-19560.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: libsndfile-1.2.2-6.el10_2.1.x86_64.rpm libsndfile-devel-1.2.2-6.el10_2.1.x86_64.rpm libsndfile-utils-1.2.2-6.el10_2.1.x86_64.rpm aarch64: libsndfile-1.2.2-6.el10_2.1.aarch64.rpm libsndfile-devel-1.2.2-6.el10_2.1.aarch64.rpm libsndfile-utils-1.2.2-6.el10_2.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/libsndfile-1.2.2-6.el10_2.1.src.rpm Related CVEs: CVE-2026-37555 Description of changes: [1.2.2-6.1] - apply patch for CVE-2026-37555 Resolves: RHEL-174531 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Critical updates for Oracle Linux 10 strengthen libsndfile against CVE-2026-37555, enhancing system security.. Oracle Linux, Security Advisory, libsndfile Update, CVE-2026-37555. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jul 17, 2026 Important Oracle
217

Oracle Linux 9 ELSA-2026-19610 Libsndfile Important Patch

The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19610 http://linux.oracle.com/errata/ELSA-2026-19610.html The following updated rpms for Oracle Linux 9 have been uploaded to the Unbreakable Linux Network: x86_64: libsndfile-1.0.31-9.el9_8.1.i686.rpm libsndfile-1.0.31-9.el9_8.1.x86_64.rpm libsndfile-devel-1.0.31-9.el9_8.1.i686.rpm libsndfile-devel-1.0.31-9.el9_8.1.x86_64.rpm libsndfile-utils-1.0.31-9.el9_8.1.x86_64.rpm aarch64: libsndfile-1.0.31-9.el9_8.1.aarch64.rpm libsndfile-devel-1.0.31-9.el9_8.1.aarch64.rpm libsndfile-utils-1.0.31-9.el9_8.1.aarch64.rpm SRPMS: http://oss.oracle.com/ol9/SRPMS-updates/libsndfile-1.0.31-9.el9_8.1.src.rpm Related CVEs: CVE-2026-37555 Description of changes: [1.0.32-9.1] - apply patch for CVE-2026-37555 Resolves: RHEL-174543 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Explore the latest security advisory for Oracle Linux 9 about libsndfile addressing an important fix for CVE-2026-37555.. Oracle Linux 9, libsndfile, important advisory, security patch, software update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Jun 24, 2026 Important Oracle
217

Oracle Linux 8 libsndfile Security Advisory ELSA-2026-19559 CVE-2026-37555

The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-19559 http://linux.oracle.com/errata/ELSA-2026-19559.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: libsndfile-1.0.28-17.el8_10.i686.rpm libsndfile-1.0.28-17.el8_10.x86_64.rpm libsndfile-devel-1.0.28-17.el8_10.i686.rpm libsndfile-devel-1.0.28-17.el8_10.x86_64.rpm libsndfile-utils-1.0.28-17.el8_10.x86_64.rpm aarch64: libsndfile-1.0.28-17.el8_10.aarch64.rpm libsndfile-devel-1.0.28-17.el8_10.aarch64.rpm libsndfile-utils-1.0.28-17.el8_10.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/libsndfile-1.0.28-17.el8_10.src.rpm Related CVEs: CVE-2026-37555 Description of changes: [1.0.28-17] - apply patch for CVE-2026-37555 Resolves: RHEL-174533 _______________________________________________ El-errata mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. https://oss.oracle.com/mailman/listinfo/el-errata . Oracle Linux 8 lsndfile Important Security Advisory ELSA-2026-19559 patch resolves CVE-2026-37555 risk.. Oracle Linux Update, Libsndfile Patch, CVE-2026-37555, Important Security Advisory, RPM Updates. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 22, 2026 Important Oracle
100

SUSE libsndfile Important Buffer Overflow Integer Overflow 2026-1968-1

An update that solves two vulnerabilities can now be installed.. # Security update for libsndfile Announcement ID: SUSE-SU-2026:1968-1 Release Date: 2026-05-18T08:14:52Z Rating: important References: * bsc#1248458 * bsc#1263695 Cross-References: * CVE-2025-52194 * CVE-2026-37555 CVSS scores: * CVE-2025-52194 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-52194 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-52194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-37555 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-37555 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-37555 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for libsndfilefixes the following issues * CVE-2025-52194: buffer overflow in the ircam_read_header function of file src/ircam.c when processing malformed IRCAM audio files (bsc#1248458). * CVE-2026-37555: IMA-ADPCM integer overflow (bsc#1263695). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-1968=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-1968=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-1968=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-1968=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-1968=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-1968=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-1968=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-1968=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-1968=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-1968=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-1968=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-1968=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) *libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Package Hub 15 15-SP7 (x86_64) * libsndfile1-32bit-debuginfo-1.0.28-150000.5.23.1 * libsndfile1-32bit-1.0.28-150000.5.23.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libsndfile1-1.0.28-150000.5.23.1 *libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libsndfile1-1.0.28-150000.5.23.1 * libsndfile-debugsource-1.0.28-150000.5.23.1 * libsndfile-devel-1.0.28-150000.5.23.1 * libsndfile1-debuginfo-1.0.28-150000.5.23.1 ## References: * https://www.suse.com/security/cve/CVE-2025-52194.html * https://www.suse.com/security/cve/CVE-2026-37555.html * https://bugzilla.suse.com/show_bug.cgi?id=1248458 * https://bugzilla.suse.com/show_bug.cgi?id=1263695 . SUSE update resolves two important security issues in libsndfile impacting audio file processing. Install now!. SUSE libsndfile important vulnerabilities audio processing update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 18, 2026 Important SuSE
100

SUSE 2026 1969-1 Libsndfile Important Buffer Overflow Integer Overflow

An update that solves two vulnerabilities can now be installed.. # Security update for libsndfile Announcement ID: SUSE-SU-2026:1969-1 Release Date: 2026-05-18T08:15:12Z Rating: important References: * bsc#1248458 * bsc#1263695 Cross-References: * CVE-2025-52194 * CVE-2026-37555 CVSS scores: * CVE-2025-52194 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-52194 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-52194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-37555 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-37555 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-37555 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for libsndfile fixes the following issues * CVE-2025-52194: buffer overflow in the ircam_read_header function of file src/ircam.c when processing malformed IRCAM audio files (bsc#1248458). * CVE-2026-37555: IMA-ADPCM integer overflow (bsc#1263695). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-1969=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-1969=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390xx86_64) * libsndfile-debugsource-1.0.25-36.32.1 * libsndfile1-debuginfo-1.0.25-36.32.1 * libsndfile1-1.0.25-36.32.1 * libsndfile-devel-1.0.25-36.32.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libsndfile1-32bit-1.0.25-36.32.1 * libsndfile1-debuginfo-32bit-1.0.25-36.32.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libsndfile1-debuginfo-1.0.25-36.32.1 * libsndfile1-32bit-1.0.25-36.32.1 * libsndfile1-1.0.25-36.32.1 * libsndfile-debugsource-1.0.25-36.32.1 * libsndfile1-debuginfo-32bit-1.0.25-36.32.1 * libsndfile-devel-1.0.25-36.32.1 ## References: * https://www.suse.com/security/cve/CVE-2025-52194.html * https://www.suse.com/security/cve/CVE-2026-37555.html * https://bugzilla.suse.com/show_bug.cgi?id=1248458 * https://bugzilla.suse.com/show_bug.cgi?id=1263695 . Critical libsndfile update addresses important buffer overflow and integer overflow issues in SUSE systems.. libsndfile security patch, SUSE important update, buffer overflow fix, integer overflow vulnerability. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 18, 2026 Important SuSE
197

Debian 11: libsndfile DLA-4402-1 CVE-2021-4156 Out-of-Bounds Read Risk

An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4402-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Bastien Roucariès December 11, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libsndfile Version : 1.0.31-2+deb11u2 CVE ID : CVE-2021-4156 Debian Bug : 1014713 An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws. For Debian 11 bullseye, this problem has been fixed in version 1.0.31-2+deb11u2. We recommend that you upgrade your libsndfile packages. For the detailed security status of libsndfile please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libsndfile Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . An out-of-bounds read in libsndfile's FLAC codec could negate security. Upgrade suggested for impacted systems.. libsndfile security issue, Debian LTS, FLAC codec update. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Dec 11, 2025 Important Debian LTS
197

Debian 11: Critical DoS Vulnerabilities Resolved in libsndfile DLA-4287-1

Two vulnerabilities have been fixed in the audio data read/write library libsndfile. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4287-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Paride Legovini August 31, 2025 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libsndfile Version : 1.0.31-2+deb11u1 CVE ID : CVE-2022-33065 CVE-2024-50612 Two vulnerabilities have been fixed in the audio data read/write library libsndfile. CVE-2022-33065 Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts. CVE-2024-50612 Out-of-bounds read in ogg_vorbis.c vorbis_analysis_wrote() can cause memory corruption when parsing a specially crafted input file. This vulnerability leads to Denial of Service (DoS). For Debian 11 bullseye, these problems have been fixed in version 1.0.31-2+deb11u1. We recommend that you upgrade your libsndfile packages. For the detailed security status of libsndfile please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libsndfile Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Essential patches address two weaknesses in libsndfile to avert DoS threats. Upgrade recommended for improved protection.. libsndfile security update, Debian LTS advisory, audio library vulnerabilities, Denial of Service, upgrade security. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Sep 01, 2025 Critical Debian LTS
172

Ubuntu 24.10 and 24.04 LTS USN-7267-2: libsndfile DoS Fix

libsndfile could be made to crash if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7267-2 February 25, 2025 libsndfile vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS Summary: libsndfile could be made to crash if it opened a specially crafted file. Software Description: - libsndfile: Library for reading/writing audio files Details: USN-7267-1 fixed a vulnerability in libsndfile. This update provides the corresponding updates for Ubuntu 24.04 LTS and Ubuntu 24.10. Original advisory details: It was discovered that libsndfile incorrectly handled certain malformed OggVorbis files. An attacker could possibly use this issue to cause libsndfile to crash, resulting in a denial of service. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 libsndfile1 1.2.2-1ubuntu5.24.10.1 sndfile-programs 1.2.2-1ubuntu5.24.10.1 Ubuntu 24.04 LTS libsndfile1 1.2.2-1ubuntu5.24.04.1 sndfile-programs 1.2.2-1ubuntu5.24.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7267-2 https://ubuntu.com/security/notices/USN-7267-1 CVE-2024-50612 Package Information: https://launchpad.net/ubuntu/+source/libsndfile/1.2.2-1ubuntu5.24.10.1 https://launchpad.net/ubuntu/+source/libsndfile/1.2.2-1ubuntu5.24.04.1 . Ubuntu Security Notice USN-7278-1 addresses a critical vulnerability in libjpeg-turbo, aimed at mitigating the risk of potential exploitation and ensuring system stability.. libsndfile Security, Crash Prevention, DoSMitigation, Ubuntu Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Feb 25, 2025 Important Ubuntu
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":0,"type":"x","order":4,"pct":0,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200