[BLFS Trac] #23177: lcms2 CVE-2026-41254

"BLFS Trac" ([email protected] via blfs-book Mailing List) <[email protected]>
Newsgroups gmane.linux.lfs.beyond.book
Message-ID <[email protected]>
#23177: lcms2 CVE-2026-41254
-------------------------+-----------------------
 Reporter:  Joe Locash   |      Owner:  blfs-book
     Type:  enhancement  |     Status:  new
 Priority:  elevated     |  Milestone:  13.1
Component:  BOOK         |    Version:  git
 Severity:  normal       |   Keywords:
-------------------------+-----------------------
 This was reported to oss-security on 4/17/26:
 https://www.openwall.com/lists/oss-security/2026/04/17/16


 {{{
 Timeline
 --------

   2010-10      CubeSize() check-after-multiply pattern introduced.
   2026-02-19   Fix 1: da6110b.
   2026-03-12   Fix 2: e0641b1.
   2026-04-13   GHSA-4xp6-rcgg-m9qq filed (private advisory).
   2026-04-14   MITRE CVE request filed (CVE Request 2025002).
                 Submitted with the evidence that existed at the time.
   2026-04-16   Asked the maintainer on the GHSA whether he'd triage,
                told him I'd publish otherwise.
   2026-04-17   GHSA closed without engagement. Public disclosure
 }}}


 This is an odd one since the changes are in upstream, but upstream didn't
 disclose the issue or respond to it. I'll attach a patch that fixes it.
-- 
Ticket URL: <https://wiki.linuxfromscratch.org/blfs/ticket/23177>
BLFS Trac <https://wiki.linuxfromscratch.org/blfs/>
Beyond Linux From Scratch

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-book
Unsubscribe: See the above information page
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.