Bug#1134690: libxpm: CVE-2026-4367
Salvatore Bonaccorso <[email protected]>
| Newsgroups | gmane.linux.debian.devel.x |
|---|---|
| Message-ID | <177693029635.457669.4011079484793260707.reportbug__21605.3055644565$1776930387$gmane$org@eldamar.lan> |
Source: libxpm Version: 1:3.5.17-1 Severity: important Tags: security upstream Forwarded: https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/31 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerability was published for libxpm. CVE-2026-4367[0]: | Out-of-bounds read in xpmNextWord() If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-4367 https://www.cve.org/CVERecord?id=CVE-2026-4367 [1] https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/31 Please adjust the affected versions in the BTS as needed. Regards, Salvatore