Release date:
2026-08-25 08:16:15 UTC
Description:
* SECURITY UPDATE: stack-based buffer overflow in the image compositor
- debian/patches/CVE-2020-35492.patch: in _inplace_src_spans() in
src/cairo-image-compositor.c, take the mask write pointer from
pixman_image_get_data(r->mask) instead of the r->_buf tail of the
stack-allocated span renderer, so a row wider than SZ_BUF (whose
mask pixman already backs with a heap allocation) can no longer be
written past the end of the stack buffer.
- CVE-2020-35492
Updated packages:
-
cairo-perf-utils_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
sha:2f44a64f17ce47b866686fd7fed3864d5ebea5d9
-
libcairo-gobject2_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
sha:c0a73767bc39d34329286510323fb8f27de91c76
-
libcairo-script-interpreter2_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
sha:8810b867bd43500f062744b4f4f111372471fc14
-
libcairo2_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
sha:d010523ad83477bf197769e3254e6085d74210b0
-
libcairo2-dev_1.15.10-2ubuntu0.1+tuxcare.els1_amd64.deb
sha:f6a16e48dfc789f78311a105bd8e9c80879cc205
-
libcairo2-doc_1.15.10-2ubuntu0.1+tuxcare.els1_all.deb
sha:0f65e106828bc43d79c269f888f0d0531f1c71de
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.