Important: libvpx security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:5537", "synopsis": "Important: libvpx security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for libvpx.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.\n\nSecurity Fix(es):\n\n* libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217)\n\n* libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2241191", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2241191", "description": ""}, {"ticket": "2241806", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2241806", "description": ""}], "cves": [{"name": "CVE-2023-44488", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-44488", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-755"}, {"name": "CVE-2023-5217", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-5217", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-119"}], "references": [], "publishedAt": "2026-03-18T06:01:13.733535Z", "rpms": {"Rocky Linux 8": {"nvras": ["libvpx-0:1.7.0-10.el8_8.src.rpm", "libvpx-debuginfo-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-0:1.7.0-10.el8_8.aarch64.rpm","libvpx-0:1.7.0-10.el8_8.i686.rpm", "libvpx-0:1.7.0-10.el8_8.x86_64.rpm", "libvpx-debuginfo-0:1.7.0-10.el8_8.i686.rpm", "libvpx-debuginfo-0:1.7.0-10.el8_8.x86_64.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.i686.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.x86_64.rpm", "libvpx-devel-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-devel-0:1.7.0-10.el8_8.i686.rpm", "libvpx-devel-0:1.7.0-10.el8_8.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important security fix available for libvpx on Rocky Linux addressing buffer overflow and crash issues. Update recommended.. Rocky Linux libvpx update, important security fix, buffer overflow in libvpx. . Severity: Important. LinuxSecurity.com Team
Important: libvpx security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:5537", "synopsis": "Important: libvpx security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for libvpx.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.\n\nSecurity Fix(es):\n\n* libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217)\n\n* libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2241191", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2241191", "description": ""}, {"ticket": "2241806", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2241806", "description": ""}], "cves": [{"name": "CVE-2023-44488", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-44488", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-755"}, {"name": "CVE-2023-5217", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-5217", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-119"}], "references": [], "publishedAt": "2026-03-18T06:01:13.733535Z", "rpms": {"Rocky Linux 8": {"nvras": ["libvpx-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-0:1.7.0-10.el8_8.i686.rpm", "libvpx-0:1.7.0-10.el8_8.src.rpm", "libvpx-0:1.7.0-10.el8_8.x86_64.rpm","libvpx-debuginfo-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-debuginfo-0:1.7.0-10.el8_8.i686.rpm", "libvpx-debuginfo-0:1.7.0-10.el8_8.x86_64.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.i686.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.x86_64.rpm", "libvpx-devel-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-devel-0:1.7.0-10.el8_8.i686.rpm", "libvpx-devel-0:1.7.0-10.el8_8.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. libvpx security update available for Rocky Linux 8 addresses important vulnerabilities including heap buffer overflow. Act now!. libvpx security update, Rocky Linux advisories, heap buffer overflow update. . Severity: Important. LinuxSecurity.com Team
Important: libvpx security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2023:5537", "synopsis": "Important: libvpx security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for libvpx.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.\n\nSecurity Fix(es):\n\n* libvpx: Heap buffer overflow in vp8 encoding in libvpx (CVE-2023-5217)\n\n* libvpx: crash related to VP9 encoding in libvpx (CVE-2023-44488)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2241191", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2241191", "description": ""}, {"ticket": "2241806", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2241806", "description": ""}], "cves": [{"name": "CVE-2023-44488", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-44488", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-755"}, {"name": "CVE-2023-5217", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2023-5217", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "cvss3BaseScore": "8.8", "cwe": "CWE-119"}], "references": [], "publishedAt": "2026-03-18T06:01:13.733535Z", "rpms": {"Rocky Linux 8": {"nvras": ["libvpx-0:1.7.0-10.el8_8.src.rpm", "libvpx-debuginfo-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-0:1.7.0-10.el8_8.aarch64.rpm","libvpx-0:1.7.0-10.el8_8.i686.rpm", "libvpx-0:1.7.0-10.el8_8.x86_64.rpm", "libvpx-debuginfo-0:1.7.0-10.el8_8.i686.rpm", "libvpx-debuginfo-0:1.7.0-10.el8_8.x86_64.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.i686.rpm", "libvpx-debugsource-0:1.7.0-10.el8_8.x86_64.rpm", "libvpx-devel-0:1.7.0-10.el8_8.aarch64.rpm", "libvpx-devel-0:1.7.0-10.el8_8.i686.rpm", "libvpx-devel-0:1.7.0-10.el8_8.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Critical libvpx security update for Rocky Linux 8 addresses important issues including heap buffer overflows and crashes. Act now!. libvpx update, Rocky Linux security, security advisories, video codec security. . Severity: Important. LinuxSecurity.com Team
Backport fix for CVE-2023-49528 and backport fixes for compatibility with Mesa 24.0.6+ / 24.1.4+ for VA-API. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-810afc5c2e 2024-07-21 01:38:57.829399 -------------------------------------------------------------------------------- Name : ffmpeg Product : Fedora 40 Version : 6.1.1 Release : 19.fc40 URL : https://ffmpeg.org/ Summary : A complete solution to record, convert and stream audio and video Description : FFmpeg is a leading multimedia framework, able to decode, encode, transcode, mux, demux, stream, filter and play pretty much anything that humans and machines have created. It supports the most obscure ancient formats up to the cutting edge. No matter if they were designed by some standards committee, the community or a corporation. This build of ffmpeg is limited in the number of codecs supported. -------------------------------------------------------------------------------- Update Information: Backport fix for CVE-2023-49528 and backport fixes for compatibility with Mesa 24.0.6+ / 24.1.4+ for VA-API -------------------------------------------------------------------------------- ChangeLog: * Sat Jul 20 2024 Neal Gompa - 6.1.1-19 - Backport fixes for Mesa 24.0.6+ / 21.1.4+ changes for VA-API * Wed Jul 17 2024 Fedora Release Engineering - 6.1.1-18 - Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild * Tue Jul 16 2024 Nicolas Chauvet - 6.1.1-17 - Rebuilt for libplacebo/vmaf * Wed Jun 19 2024 Dominik Mierzejewski - 6.1.1-16 - Backport fix for CVE-2023-49528 * Thu Jun 13 2024 Sandro Mani - 6.1.1-15 - Rebuild for tesseract-5.4.1 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2274694 - CVE-2023-49528 ffmpeg: Heap Buffer Overflow vulnerability [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2274694 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-810afc5c2e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.