Debian alert DLA-4644-1 (libmatio)
| From: | Andreas Henriksson <andreas@fatal.se> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 4644-1] libmatio security update | |
| Date: | Wed, 24 Jun 2026 14:19:33 +0200 | |
| Message-ID: | <ahkzhuh2vfsadb3i7lcrsi3lanp2rp7nahvr5cs4l4uc5qcgkr@fokpflgd6r7x> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4644-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andreas Henriksson June 24, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libmatio Version : 1.5.23-2+deb12u1 CVE ID : CVE-2025-2337 CVE-2025-2338 CVE-2025-50343 Debian Bug : 1100992 1104247 1124797 Multiple vulnerabilities has been discovered in libmatio, a MAT File I/O Library. CVE-2025-2337 A vulnerability, which was classified as critical, has been found in libmatio Mat_VarPrint function. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. CVE-2025-2338 A Denial of Service (DoS) and head-based buffer overflow was found, which could potentially lead to remote code execution if libmatio is embedded in services that accepts user-supplied .mat files. CVE-2025-50343 A Denial of Service (DoS) and in certain cases heap corruption vulnerability was found, which could lead to potential remote code execution if libmatio is embedded in services that accepts user-supplied .mat files. For Debian 12 bookworm, these problems have been fixed in version 1.5.23-2+deb12u1. For Debian 11 bullseye, see separate DLA-4459-1. We recommend that you upgrade your libmatio packages. For the detailed security status of libmatio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libmatio Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+uHltkZSvnmOJ4zCC8R9xk0TUwYFAmo7y1IACgkQC8R9xk0T UwZ1axAAh7444g6Jg6Y1buzaHpjkwbK61YbuUojXdBFZlZ+pWCIR0UjnK1R3LRJ5 l5IjztVuiS17DcszOGAJ2/olokMRydQA9g7DfJzWxC90rRCZJkjE9la3jisgnGHJ 1FVyuoeR0SLM5fUNGyKa8hLrGmfxVWGUcN91bNDZRCVJUKYzlmbzH6zbovHVqEtu kchhvEyZ5Z6hhWpyWIsYG07mInNzKAZUq1cSSV1bX2GO3XQSbEEZ0yJQYspUmtwF IR7YpyethzKx7HUPBkcOJj1qW/9cZw0a4njoo+FLy+KRdWVpY7ljpns4On5u8HNF AGjBlyrHawLAW+RA1xQdcpYFWlzQMZRXX6KF2ZTh5EwbF09uUMW0lYUjm+fg5alP 9ewgKMSZUwoNzzjJ/1cHs2dlNVqQwc6KVbhQJDIAXrvz5wH6HuBkA6FcscsVC2EI bTKaL5uF+Nf3rNv3IKNAlVthj+vOCk7Lc18hh7CA8nRT24PMeb5/04Q1+MgqbGu1 ZNMyekHjuCx6CI12IZi7X7gBOhlqC7tirpRFzAixgxvQfFtFf2p4q+PDqWj+2Iqc vGcFeNb6HiuDs6M+PM8SpIctENpV+nrd882/pFptqPBFDamdUdYtbtPdo267eZS1 E9UzP1PXmOmHclVjAhpr2mu9djvdknKb0pPMpUKRntfPwRmP1cs= =z0DJ -----END PGP SIGNATURE-----
