ALAS-2025-902


Amazon Linux 2023 Security Advisory: ALAS-2025-902
Advisory Release Date: 2025-03-13 04:48 Pacific
Advisory Updated Date: 2025-03-13 04:48 Pacific
Severity: Medium

Issue Overview:

libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read. (CVE-2024-50612)


Affected Packages:

libsndfile


Issue Correction:
Run dnf update libsndfile --releasever 2023.6.20250317 to update your system.

New Packages:
aarch64:
    libsndfile-utils-1.2.2-3.amzn2023.0.3.aarch64
    libsndfile-devel-1.2.2-3.amzn2023.0.3.aarch64
    libsndfile-utils-debuginfo-1.2.2-3.amzn2023.0.3.aarch64
    libsndfile-debuginfo-1.2.2-3.amzn2023.0.3.aarch64
    libsndfile-1.2.2-3.amzn2023.0.3.aarch64
    libsndfile-debugsource-1.2.2-3.amzn2023.0.3.aarch64

src:
    libsndfile-1.2.2-3.amzn2023.0.3.src

x86_64:
    libsndfile-debugsource-1.2.2-3.amzn2023.0.3.x86_64
    libsndfile-debuginfo-1.2.2-3.amzn2023.0.3.x86_64
    libsndfile-utils-1.2.2-3.amzn2023.0.3.x86_64
    libsndfile-utils-debuginfo-1.2.2-3.amzn2023.0.3.x86_64
    libsndfile-1.2.2-3.amzn2023.0.3.x86_64
    libsndfile-devel-1.2.2-3.amzn2023.0.3.x86_64