Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:5319 - Security Advisory
Issued:
2026-03-23
Updated:
2026-03-23

RHSA-2026:5319 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: libvpx security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for libvpx is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The libvpx packages provide the VP8 SDK, which allows the encoding and decoding of the VP8 video codec, commonly used with the WebM multimedia container file format.

Security Fix(es):

  • libvpx: Heap buffer overflow in libvpx (CVE-2026-2447)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux Server - AUS 9.2 x86_64
  • Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le
  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64
  • Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x
  • Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64
  • Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64
  • Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le
  • Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x

Fixes

  • BZ - 2440219 - CVE-2026-2447 libvpx: Heap buffer overflow in libvpx

CVEs

  • CVE-2026-2447

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux Server - AUS 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
x86_64
libvpx-1.9.0-7.el9_2.3.i686.rpm SHA-256: 39e0a9bc7b8217019df1d8f05eb03c8b15478960e8e228a2a2d9c4bbd96c256c
libvpx-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: a731cf985bdcbc8298c95ab670c63c38f857faecfbe1af258965e95fa02385f6
libvpx-debuginfo-1.9.0-7.el9_2.3.i686.rpm SHA-256: eeb0400fba80f174e90ad08520312979d36150b9dcb594225191eda52d9ae00e
libvpx-debuginfo-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: 6231e6ce4b1bc348b7ce271f4a80101578d1c7af221a8729377646d3a5041a8f
libvpx-debugsource-1.9.0-7.el9_2.3.i686.rpm SHA-256: 005d350ba4860f7c26790a1cf10c893fb19044bf380968879464cc03171eb209
libvpx-debugsource-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: d8ec3a0786acc5550c78435b3b88a3be055d45437fa16a718284bf3219cdec01
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.i686.rpm SHA-256: 6cd0a39972d044ee8586b90115f6f4049c187eb28aa39bc0c2e20f1cff95687d
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: 58f3ebd32f152f37f60df4a8bd4200f22326fc78e864d0686d08108874703286

Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
ppc64le
libvpx-1.9.0-7.el9_2.3.ppc64le.rpm SHA-256: ed080eb5803e6117e406276fbfe18742928ac303527ac37fce261fc27d30e3e9
libvpx-debuginfo-1.9.0-7.el9_2.3.ppc64le.rpm SHA-256: 63bb41565b2424830d4598b34df71ed4143f2d95a005f2170cf474d720f05d5c
libvpx-debugsource-1.9.0-7.el9_2.3.ppc64le.rpm SHA-256: 04ddabe51d293164ef4b38dd75f29394ce65e57a65c7d29973984bda80413bec
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.ppc64le.rpm SHA-256: 96ea52f783d59800029cb42f6cf41a1bc1e40c604e995b01dc129dee1d677e8c

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
x86_64
libvpx-1.9.0-7.el9_2.3.i686.rpm SHA-256: 39e0a9bc7b8217019df1d8f05eb03c8b15478960e8e228a2a2d9c4bbd96c256c
libvpx-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: a731cf985bdcbc8298c95ab670c63c38f857faecfbe1af258965e95fa02385f6
libvpx-debuginfo-1.9.0-7.el9_2.3.i686.rpm SHA-256: eeb0400fba80f174e90ad08520312979d36150b9dcb594225191eda52d9ae00e
libvpx-debuginfo-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: 6231e6ce4b1bc348b7ce271f4a80101578d1c7af221a8729377646d3a5041a8f
libvpx-debugsource-1.9.0-7.el9_2.3.i686.rpm SHA-256: 005d350ba4860f7c26790a1cf10c893fb19044bf380968879464cc03171eb209
libvpx-debugsource-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: d8ec3a0786acc5550c78435b3b88a3be055d45437fa16a718284bf3219cdec01
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.i686.rpm SHA-256: 6cd0a39972d044ee8586b90115f6f4049c187eb28aa39bc0c2e20f1cff95687d
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: 58f3ebd32f152f37f60df4a8bd4200f22326fc78e864d0686d08108874703286

Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
aarch64
libvpx-1.9.0-7.el9_2.3.aarch64.rpm SHA-256: 30e4019d3920dd7c940c5a21e41f6924fae11c8e43ad17b92e5134188c85cd14
libvpx-debuginfo-1.9.0-7.el9_2.3.aarch64.rpm SHA-256: c1053061d2a64fa4bb627cd91583b9aa9f9fdd4829ade1f9d104c32e660b4fb8
libvpx-debugsource-1.9.0-7.el9_2.3.aarch64.rpm SHA-256: 1e8ba9c63863e8624e116caa2ae88a27482961fc5c09fea4c1c4bf1b5eb75062
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.aarch64.rpm SHA-256: a5e93a462654489adfa67e1d45bd375ca4a2c3624a20724a73a1cae1ec22f24a

Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
s390x
libvpx-1.9.0-7.el9_2.3.s390x.rpm SHA-256: 2a18ee661eea9e7301d1b00c1aedf7be1edd0d02339eb0bb014501e54b3437ef
libvpx-debuginfo-1.9.0-7.el9_2.3.s390x.rpm SHA-256: babb64596690f5733ef8d1d4f8061c17580887315940ab692e800f5157a190f7
libvpx-debugsource-1.9.0-7.el9_2.3.s390x.rpm SHA-256: 5171f8a28a98c3d47ce0f680ec82f7247b7c49c632e92b6ebb53c376db1c520f
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.s390x.rpm SHA-256: 2bde6b93513a77424dd9744c35a3a9b068c44a23b804b07af6a57c333e9093c4

Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
x86_64
libvpx-1.9.0-7.el9_2.3.i686.rpm SHA-256: 39e0a9bc7b8217019df1d8f05eb03c8b15478960e8e228a2a2d9c4bbd96c256c
libvpx-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: a731cf985bdcbc8298c95ab670c63c38f857faecfbe1af258965e95fa02385f6
libvpx-debuginfo-1.9.0-7.el9_2.3.i686.rpm SHA-256: eeb0400fba80f174e90ad08520312979d36150b9dcb594225191eda52d9ae00e
libvpx-debuginfo-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: 6231e6ce4b1bc348b7ce271f4a80101578d1c7af221a8729377646d3a5041a8f
libvpx-debugsource-1.9.0-7.el9_2.3.i686.rpm SHA-256: 005d350ba4860f7c26790a1cf10c893fb19044bf380968879464cc03171eb209
libvpx-debugsource-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: d8ec3a0786acc5550c78435b3b88a3be055d45437fa16a718284bf3219cdec01
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.i686.rpm SHA-256: 6cd0a39972d044ee8586b90115f6f4049c187eb28aa39bc0c2e20f1cff95687d
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.x86_64.rpm SHA-256: 58f3ebd32f152f37f60df4a8bd4200f22326fc78e864d0686d08108874703286

Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
aarch64
libvpx-1.9.0-7.el9_2.3.aarch64.rpm SHA-256: 30e4019d3920dd7c940c5a21e41f6924fae11c8e43ad17b92e5134188c85cd14
libvpx-debuginfo-1.9.0-7.el9_2.3.aarch64.rpm SHA-256: c1053061d2a64fa4bb627cd91583b9aa9f9fdd4829ade1f9d104c32e660b4fb8
libvpx-debugsource-1.9.0-7.el9_2.3.aarch64.rpm SHA-256: 1e8ba9c63863e8624e116caa2ae88a27482961fc5c09fea4c1c4bf1b5eb75062
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.aarch64.rpm SHA-256: a5e93a462654489adfa67e1d45bd375ca4a2c3624a20724a73a1cae1ec22f24a

Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
ppc64le
libvpx-1.9.0-7.el9_2.3.ppc64le.rpm SHA-256: ed080eb5803e6117e406276fbfe18742928ac303527ac37fce261fc27d30e3e9
libvpx-debuginfo-1.9.0-7.el9_2.3.ppc64le.rpm SHA-256: 63bb41565b2424830d4598b34df71ed4143f2d95a005f2170cf474d720f05d5c
libvpx-debugsource-1.9.0-7.el9_2.3.ppc64le.rpm SHA-256: 04ddabe51d293164ef4b38dd75f29394ce65e57a65c7d29973984bda80413bec
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.ppc64le.rpm SHA-256: 96ea52f783d59800029cb42f6cf41a1bc1e40c604e995b01dc129dee1d677e8c

Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2

SRPM
libvpx-1.9.0-7.el9_2.3.src.rpm SHA-256: 5271f179bda410dfbf0b15d4b4e02f295790c0c3cf5876fe12f66b6f46403321
s390x
libvpx-1.9.0-7.el9_2.3.s390x.rpm SHA-256: 2a18ee661eea9e7301d1b00c1aedf7be1edd0d02339eb0bb014501e54b3437ef
libvpx-debuginfo-1.9.0-7.el9_2.3.s390x.rpm SHA-256: babb64596690f5733ef8d1d4f8061c17580887315940ab692e800f5157a190f7
libvpx-debugsource-1.9.0-7.el9_2.3.s390x.rpm SHA-256: 5171f8a28a98c3d47ce0f680ec82f7247b7c49c632e92b6ebb53c376db1c520f
libvpx-utils-debuginfo-1.9.0-7.el9_2.3.s390x.rpm SHA-256: 2bde6b93513a77424dd9744c35a3a9b068c44a23b804b07af6a57c333e9093c4

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility