[CLSA-2026:1787645764] Fix CVE(s): CVE-2020-35492
Type:
security
Severity:
Important
Release date:
2026-08-25 08:16:15 UTC
Description:
* SECURITY UPDATE: stack-based buffer overflow in the image compositor - debian/patches/CVE-2020-35492.patch: in _inplace_src_spans() in src/cairo-image-compositor.c, take the mask write pointer from pixman_image_get_data(r->mask) instead of the r->_buf tail of the stack-allocated span renderer, so a row wider than SZ_BUF (whose mask pixman already backs with a heap allocation) can no longer be written past the end of the stack buffer. - CVE-2020-35492
CVEs fixed:
Updated packages:
  • cairo-perf-utils_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:2f44a64f17ce47b866686fd7fed3864d5ebea5d9
  • libcairo-gobject2_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:c0a73767bc39d34329286510323fb8f27de91c76
  • libcairo-script-interpreter2_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:8810b867bd43500f062744b4f4f111372471fc14
  • libcairo2_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:d010523ad83477bf197769e3254e6085d74210b0
  • libcairo2-dev_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:f6a16e48dfc789f78311a105bd8e9c80879cc205
  • libcairo2-doc_1.15.10-2ubuntu0.1+tuxcare.els1_all.deb
    sha:0f65e106828bc43d79c269f888f0d0531f1c71de
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.