Opened 8 months ago

Closed 8 months ago

#22808 closed enhancement (fixed)

librsvg-2.61.4

Reported by: Bruce Dubbs Owned by: Douglas R. Reno
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New minor version.

Change History (3)

comment:1 by Douglas R. Reno, 8 months ago

Owner: changed from blfs-book to Douglas R. Reno
Priority: normal → elevated
Status: new → assigned

These are both security updates, so let's get them in now...

comment:2 by Douglas R. Reno, 8 months ago

Release notes:

Release notes
Version 2.61.4

librsvg crate version 2.61.4

librsvg-rebind crate version 0.2.1

    #1225 (closed): Update the time crate to 0.3.47 for RUSTSEC-2026-0009

    Fix the check for cargo-cbuild in meson.build.

Security Information

​https://rustsec.org/advisories/RUSTSEC-2026-0009.html

Impact: "When user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario."

This was assigned CVE-2026-25727, and is a denial of service issue.

comment:3 by Douglas R. Reno, 8 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at e2f8fcd2c0eb27eddd4a6b4747f532d1da2885b0

SA-12.4-098 issued

Note: See TracTickets for help on using tickets.