[CLSA-2025:1755003990] libvpx: Fix of CVE-2024-5197
Type:
security
Severity:
Critical
Release date:
2025-08-12 13:06:34 UTC
Description:
- CVE-2024-5197: fix integer overflows in image allocation and wrapping logic, validate dimensions and alignment to prevent invalid buffer calculations
Updated packages:
  • libvpx-1.9.0-7.el9_2.alma.1.tuxcare.els1.i686.rpm
    sha:a4b50d616879959eab67bb5a0a8df4622503d35af3d35362a3b28a6a65a35046
  • libvpx-1.9.0-7.el9_2.alma.1.tuxcare.els1.x86_64.rpm
    sha:3e9048aa1ab580b84782f6768526b4ca201ecc7389bfbea49eceb704588446fb
  • libvpx-devel-1.9.0-7.el9_2.alma.1.tuxcare.els1.i686.rpm
    sha:a65b906551b6061f23219028980c53a1ec1c833f4829e90fac0b7b97a3b36963
  • libvpx-devel-1.9.0-7.el9_2.alma.1.tuxcare.els1.x86_64.rpm
    sha:72d77d14a7506a02947b818a1c3f6a629abe661d0fccc0b171952ada895f97b6
  • libvpx-utils-1.9.0-7.el9_2.alma.1.tuxcare.els1.x86_64.rpm
    sha:c89d0f9d254b627f5b4a873fe1b8d0f59e71391efaffa51925e7db305eed73c8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.