ELA-1666-1 libvpx security update

buffer overflow

2026-03-27
Packagelibvpx
Version1.6.1-3+deb9u8 (stretch), 1.7.0-3+deb10u5 (buster)
Related CVEs CVE-2026-2447


A buffer overflow was discovered in libvpx, a library implementing the VP8/VP9 open video codecs, which could result in denial of service or potentially the execution of arbitrary code.



For Debian 10 buster, these problems have been fixed in version 1.7.0-3+deb10u5.

For Debian 9 stretch, these problems have been fixed in version 1.6.1-3+deb9u8.

We recommend that you upgrade your libvpx packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.