Opened 8 months ago
Closed 8 months ago
#22808 closed enhancement (fixed)
librsvg-2.61.4
| Reported by: | Bruce Dubbs | Owned by: | Douglas R. Reno |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New minor version.
Change History (3)
comment:1 by , 8 months ago
| Owner: | changed from to |
|---|---|
| Priority: | normal → elevated |
| Status: | new → assigned |
comment:2 by , 8 months ago
Release notes:
Release notes
Version 2.61.4
librsvg crate version 2.61.4
librsvg-rebind crate version 0.2.1
#1225 (closed): Update the time crate to 0.3.47 for RUSTSEC-2026-0009
Fix the check for cargo-cbuild in meson.build.
Security Information
https://rustsec.org/advisories/RUSTSEC-2026-0009.html
Impact: "When user-provided input is provided to any type that parses with the RFC 2822 format, a denial of service attack via stack exhaustion is possible. The attack relies on formally deprecated and rarely-used features that are part of the RFC 2822 format used in a malicious manner. Ordinary, non-malicious input will never encounter this scenario."
This was assigned CVE-2026-25727, and is a denial of service issue.
comment:3 by , 8 months ago
| Resolution: | → fixed |
|---|---|
| Status: | assigned → closed |
Fixed at e2f8fcd2c0eb27eddd4a6b4747f532d1da2885b0
SA-12.4-098 issued

These are both security updates, so let's get them in now...