------------------------------------------------------------------------- Debian LTS Advisory DLA-4644-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Andreas Henriksson June 24, 2026 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libmatio Version : 1.5.23-2+deb12u1 CVE ID : CVE-2025-2337 CVE-2025-2338 CVE-2025-50343 Debian Bug : 1100992 1104247 1124797 Multiple vulnerabilities has been discovered in libmatio, a MAT File I/O Library. CVE-2025-2337 A vulnerability, which was classified as critical, has been found in libmatio Mat_VarPrint function. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. CVE-2025-2338 A Denial of Service (DoS) and head-based buffer overflow was found, which could potentially lead to remote code execution if libmatio is embedded in services that accepts user-supplied .mat files. CVE-2025-50343 A Denial of Service (DoS) and in certain cases heap corruption vulnerability was found, which could lead to potential remote code execution if libmatio is embedded in services that accepts user-supplied .mat files. For Debian 12 bookworm, these problems have been fixed in version 1.5.23-2+deb12u1. For Debian 11 bullseye, see separate DLA-4459-1. We recommend that you upgrade your libmatio packages. For the detailed security status of libmatio please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libmatio Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: PGP signature