Amazon Linux 2023 Security Advisory: ALAS-2025-902
Advisory Release Date: 2025-03-13 04:48 Pacific
Advisory Updated Date: 2025-03-13 04:48 Pacific
libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read. (CVE-2024-50612)
Affected Packages:
libsndfile
Issue Correction:
Run dnf update libsndfile --releasever 2023.6.20250317 to update your system.
aarch64:
libsndfile-utils-1.2.2-3.amzn2023.0.3.aarch64
libsndfile-devel-1.2.2-3.amzn2023.0.3.aarch64
libsndfile-utils-debuginfo-1.2.2-3.amzn2023.0.3.aarch64
libsndfile-debuginfo-1.2.2-3.amzn2023.0.3.aarch64
libsndfile-1.2.2-3.amzn2023.0.3.aarch64
libsndfile-debugsource-1.2.2-3.amzn2023.0.3.aarch64
src:
libsndfile-1.2.2-3.amzn2023.0.3.src
x86_64:
libsndfile-debugsource-1.2.2-3.amzn2023.0.3.x86_64
libsndfile-debuginfo-1.2.2-3.amzn2023.0.3.x86_64
libsndfile-utils-1.2.2-3.amzn2023.0.3.x86_64
libsndfile-utils-debuginfo-1.2.2-3.amzn2023.0.3.x86_64
libsndfile-1.2.2-3.amzn2023.0.3.x86_64
libsndfile-devel-1.2.2-3.amzn2023.0.3.x86_64