Skip to content

[Deepin Integration]~[v25-Release] fix(cve): CVE-2026-52584 - apng: guard decoded frame row bounds by hudeng-go@deepin-community/jpeg-xl by deepin-community-ci-bot[bot] #13893

Description

@deepin-bot

Package information | 软件包信息

包名 版本
jpeg-xl 0.7.0-10.2deepin3

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4514/testing/ ./

Changelog | 更新信息

jpeg-xl (0.7.0-10.2deepin3) unstable; urgency=medium

  • Fix CVE-2026-52584: heap buffer overflow in DecodeImageAPNG
    Guard the decoded PNG frame's row array before copying pixel rows.
    A crafted APNG with a frame viewport larger than the rows actually
    produced could cause an out-of-bounds read.

Metadata

Metadata

Assignees

Type

No type

Projects

Status
已集成

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions