[CLSA-2026:1787646995] Fix CVE(s): CVE-2020-23922, CVE-2021-40633, CVE-2026-23868
Type:
security
Severity:
Important
Release date:
2026-08-25 08:36:48 UTC
Description:
* SECURITY UPDATE: heap buffer over-read in gif2rgb - debian/patches/CVE-2020-23922.patch: bound each pixel index against the active color table before indexing ColorMap->Colors in DumpScreen2RGB in util/gif2rgb.c. - CVE-2020-23922 * SECURITY UPDATE: memory leak leading to denial of service - debian/patches/CVE-2021-40633.patch: free every ScreenBuffer row, not just the row-pointer array, at the end of GIF2RGB in util/gif2rgb.c. - CVE-2021-40633 * SECURITY UPDATE: double free in GifMakeSavedImage - debian/patches/CVE-2026-23868.patch: null out the heap pointers aliased by the shallow copy of CopyFrom, test the source record when deciding what to deep-copy, and restore ExtensionBlockCount after the extension blocks are copied, in lib/gifalloc.c. - CVE-2026-23868
Updated packages:
  • giflib-tools_5.1.4-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:9cca7b0244b450b4cc338ed8591466ba0acfde53
  • libgif-dev_5.1.4-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:2c33b893c22c359fd8c7ec70497c55908d32614c
  • libgif7_5.1.4-2ubuntu0.1+tuxcare.els1_amd64.deb
    sha:83e03f7315f9ae228e5ac431eb38eeab56a92172
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.