Skip to content

[Deepin Integration]~[v25-Release] fix(cve): CVE-2026-52584 - apng: guard decoded frame row bounds by hudeng-go@deepin-community/jpeg-xl by deepin-community-ci-bot[bot] #13893

Description

@deepin-bot

Package information | 软件包信息

包名 版本
jpeg-xl 0.7.0-10.2deepin3

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4514/testing/ ./

Changelog | 更新信息

jpeg-xl (0.7.0-10.2deepin3) unstable; urgency=medium

  • Fix CVE-2026-52584: heap buffer overflow in DecodeImageAPNG
    Guard the decoded PNG frame's row array before copying pixel rows.
    A crafted APNG with a frame viewport larger than the rows actually
    produced could cause an out-of-bounds read.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions