[BLFS Trac] #23177: lcms2 CVE-2026-41254
| Newsgroups | gmane.linux.lfs.beyond.book |
|---|---|
| Message-ID | <[email protected]> |
#23177: lcms2 CVE-2026-41254
-------------------------+-----------------------
Reporter: Joe Locash | Owner: blfs-book
Type: enhancement | Status: new
Priority: elevated | Milestone: 13.1
Component: BOOK | Version: git
Severity: normal | Keywords:
-------------------------+-----------------------
This was reported to oss-security on 4/17/26:
https://www.openwall.com/lists/oss-security/2026/04/17/16
{{{
Timeline
--------
2010-10 CubeSize() check-after-multiply pattern introduced.
2026-02-19 Fix 1: da6110b.
2026-03-12 Fix 2: e0641b1.
2026-04-13 GHSA-4xp6-rcgg-m9qq filed (private advisory).
2026-04-14 MITRE CVE request filed (CVE Request 2025002).
Submitted with the evidence that existed at the time.
2026-04-16 Asked the maintainer on the GHSA whether he'd triage,
told him I'd publish otherwise.
2026-04-17 GHSA closed without engagement. Public disclosure
}}}
This is an odd one since the changes are in upstream, but upstream didn't
disclose the issue or respond to it. I'll attach a patch that fixes it.
--
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23177>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch
--
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page