Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:4447 - Security Advisory
Issued:
2026-03-12
Updated:
2026-03-12

RHSA-2026:4447 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libvpx security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libvpx is now available for Red Hat Enterprise Linux 9.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.

Security Fix(es):

  • libvpx: Heap buffer overflow in libvpx (CVE-2026-2447)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 9 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 9 s390x
  • Red Hat Enterprise Linux for Power, little endian 9 ppc64le
  • Red Hat Enterprise Linux for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for x86_64 9 x86_64
  • Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le
  • Red Hat CodeReady Linux Builder for ARM 64 9 aarch64
  • Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x

Fixes

  • BZ - 2440219 - CVE-2026-2447 libvpx: Heap buffer overflow in libvpx

CVEs

  • CVE-2026-2447

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 9

SRPM
libvpx-1.9.0-10.el9_7.src.rpm SHA-256: 714280f564e94946719954ea1a6f45eed0eadf80b47407b0eb6b815e08ea705a
x86_64
libvpx-1.9.0-10.el9_7.i686.rpm SHA-256: 0ad679b9d1d1d9e6a230c792193acfb363544fdcef8d3a84478a190587ffb053
libvpx-1.9.0-10.el9_7.x86_64.rpm SHA-256: 117a3e2c701089c8209af606371c391a94bb8c91425e4b0681eaa04639f86253
libvpx-debuginfo-1.9.0-10.el9_7.i686.rpm SHA-256: bb92d1a41751e10171bec6681993cbece1919a0dd0ea6bf5ce9aabacdab9d49b
libvpx-debuginfo-1.9.0-10.el9_7.x86_64.rpm SHA-256: 14310653b47afa1dc601f20fbdc5a1d888633395b93dbb09fc8c6533c73aabe8
libvpx-debugsource-1.9.0-10.el9_7.i686.rpm SHA-256: 22660112d01f19bf81e5d76d4650f9182a8e3621e968457ee9f54776c7e9ac45
libvpx-debugsource-1.9.0-10.el9_7.x86_64.rpm SHA-256: bdd6d287ff41811fa6ebb7f6fd5d9e9dd7d5c4981c707cc472a25e623996d58f
libvpx-utils-debuginfo-1.9.0-10.el9_7.i686.rpm SHA-256: 4d49608d3202b39783fdcc209ef50bff97a131303ca3258018e38a77422c5400
libvpx-utils-debuginfo-1.9.0-10.el9_7.x86_64.rpm SHA-256: dc0b2c3fd49d94fd5b40917083136edf3905d0e69f5bdd1e5a73ad4567744375

Red Hat Enterprise Linux for IBM z Systems 9

SRPM
libvpx-1.9.0-10.el9_7.src.rpm SHA-256: 714280f564e94946719954ea1a6f45eed0eadf80b47407b0eb6b815e08ea705a
s390x
libvpx-1.9.0-10.el9_7.s390x.rpm SHA-256: 011de31f41da349d9c44c596a345f2d54add49908a1e34572713c130f3c45626
libvpx-debuginfo-1.9.0-10.el9_7.s390x.rpm SHA-256: fdef49c473cdd8a0a5bb4231586e5f2b6524eab70e24ce9233724684a851357e
libvpx-debugsource-1.9.0-10.el9_7.s390x.rpm SHA-256: 76c28e8d4b0e34f637a57377774ed829f8fa914621f9995e024af585eef26d29
libvpx-utils-debuginfo-1.9.0-10.el9_7.s390x.rpm SHA-256: bcda6ddd4f32b316004fa9f6090d48f10bbf73e93d6c980579eecfcf66ebec61

Red Hat Enterprise Linux for Power, little endian 9

SRPM
libvpx-1.9.0-10.el9_7.src.rpm SHA-256: 714280f564e94946719954ea1a6f45eed0eadf80b47407b0eb6b815e08ea705a
ppc64le
libvpx-1.9.0-10.el9_7.ppc64le.rpm SHA-256: 32b151230a1fe63f6f48a2ddcb592e76d4660eab62c5823f6eabe89112841f59
libvpx-debuginfo-1.9.0-10.el9_7.ppc64le.rpm SHA-256: 0e893ad913ab7112bedd071d21e8ced7e34febac4118e9cf52063f64bb976687
libvpx-debugsource-1.9.0-10.el9_7.ppc64le.rpm SHA-256: 65b3181a16b76cc46a0d7cc76b104d9993e9490e29bccdf020d5f575a0763cc8
libvpx-utils-debuginfo-1.9.0-10.el9_7.ppc64le.rpm SHA-256: 1cf5ac509b996e2b71e8cc6fa38dc079267b1a72f90667853404c6d65a37505d

Red Hat Enterprise Linux for ARM 64 9

SRPM
libvpx-1.9.0-10.el9_7.src.rpm SHA-256: 714280f564e94946719954ea1a6f45eed0eadf80b47407b0eb6b815e08ea705a
aarch64
libvpx-1.9.0-10.el9_7.aarch64.rpm SHA-256: 3b9715904120ed47c43861ff706323ab610fc9ca4ace8334d8e0afdb219e56eb
libvpx-debuginfo-1.9.0-10.el9_7.aarch64.rpm SHA-256: 461dd00d9607de072f6d1acd090f9618ce0dc459e64c18d0aa1ccf750586a4dc
libvpx-debugsource-1.9.0-10.el9_7.aarch64.rpm SHA-256: 8ed9e59f8f499df786caf3b8b22b56850fd1a1d463919c6fded049a4c6affaae
libvpx-utils-debuginfo-1.9.0-10.el9_7.aarch64.rpm SHA-256: ded4f1016dee8f92225091199186fb6b8117528117299924d607020f2d8f1b49

Red Hat CodeReady Linux Builder for x86_64 9

SRPM
x86_64
libvpx-debuginfo-1.9.0-10.el9_7.i686.rpm SHA-256: bb92d1a41751e10171bec6681993cbece1919a0dd0ea6bf5ce9aabacdab9d49b
libvpx-debuginfo-1.9.0-10.el9_7.x86_64.rpm SHA-256: 14310653b47afa1dc601f20fbdc5a1d888633395b93dbb09fc8c6533c73aabe8
libvpx-debugsource-1.9.0-10.el9_7.i686.rpm SHA-256: 22660112d01f19bf81e5d76d4650f9182a8e3621e968457ee9f54776c7e9ac45
libvpx-debugsource-1.9.0-10.el9_7.x86_64.rpm SHA-256: bdd6d287ff41811fa6ebb7f6fd5d9e9dd7d5c4981c707cc472a25e623996d58f
libvpx-devel-1.9.0-10.el9_7.i686.rpm SHA-256: a4588b8a723d7122b2f03a031ed824ed103226f1dc94478a67615af07b27cb32
libvpx-devel-1.9.0-10.el9_7.x86_64.rpm SHA-256: 426afb9ad83216f4e745eac8b41eed80ad3c246f1e67cf681e00ff07d26a50bd
libvpx-utils-debuginfo-1.9.0-10.el9_7.i686.rpm SHA-256: 4d49608d3202b39783fdcc209ef50bff97a131303ca3258018e38a77422c5400
libvpx-utils-debuginfo-1.9.0-10.el9_7.x86_64.rpm SHA-256: dc0b2c3fd49d94fd5b40917083136edf3905d0e69f5bdd1e5a73ad4567744375

Red Hat CodeReady Linux Builder for Power, little endian 9

SRPM
ppc64le
libvpx-debuginfo-1.9.0-10.el9_7.ppc64le.rpm SHA-256: 0e893ad913ab7112bedd071d21e8ced7e34febac4118e9cf52063f64bb976687
libvpx-debugsource-1.9.0-10.el9_7.ppc64le.rpm SHA-256: 65b3181a16b76cc46a0d7cc76b104d9993e9490e29bccdf020d5f575a0763cc8
libvpx-devel-1.9.0-10.el9_7.ppc64le.rpm SHA-256: 9cc90de18a7d08951f9010e535ee51b7f476c3e773f7ceffe23d6d382b63f0f1
libvpx-utils-debuginfo-1.9.0-10.el9_7.ppc64le.rpm SHA-256: 1cf5ac509b996e2b71e8cc6fa38dc079267b1a72f90667853404c6d65a37505d

Red Hat CodeReady Linux Builder for ARM 64 9

SRPM
aarch64
libvpx-debuginfo-1.9.0-10.el9_7.aarch64.rpm SHA-256: 461dd00d9607de072f6d1acd090f9618ce0dc459e64c18d0aa1ccf750586a4dc
libvpx-debugsource-1.9.0-10.el9_7.aarch64.rpm SHA-256: 8ed9e59f8f499df786caf3b8b22b56850fd1a1d463919c6fded049a4c6affaae
libvpx-devel-1.9.0-10.el9_7.aarch64.rpm SHA-256: 43e5f44ee95f6c76bf8a115d3d6644949894a073b9de7e89ab001fcbbd0c196b
libvpx-utils-debuginfo-1.9.0-10.el9_7.aarch64.rpm SHA-256: ded4f1016dee8f92225091199186fb6b8117528117299924d607020f2d8f1b49

Red Hat CodeReady Linux Builder for IBM z Systems 9

SRPM
s390x
libvpx-debuginfo-1.9.0-10.el9_7.s390x.rpm SHA-256: fdef49c473cdd8a0a5bb4231586e5f2b6524eab70e24ce9233724684a851357e
libvpx-debugsource-1.9.0-10.el9_7.s390x.rpm SHA-256: 76c28e8d4b0e34f637a57377774ed829f8fa914621f9995e024af585eef26d29
libvpx-devel-1.9.0-10.el9_7.s390x.rpm SHA-256: 450c6a7cb65356f87f16bc77ca41b9df7e166e92a334dcb6fc6d329c41168074
libvpx-utils-debuginfo-1.9.0-10.el9_7.s390x.rpm SHA-256: bcda6ddd4f32b316004fa9f6090d48f10bbf73e93d6c980579eecfcf66ebec61

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility