Opened 5 months ago

Closed 5 months ago

#23175 closed enhancement (fixed)

libXpm-3.5.19 (Xorg library)

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

Change History (4)

comment:1 by Joe Locash, 5 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:2 by Joe Locash, 5 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 459ccdf217. Leaving open for SA.

comment:3 by Douglas R. Reno, 5 months ago

Offline copy of the security advisory:

======================================================================
X.Org Security Advisory: April 21, 2026

Issue in libXpm prior to version 3.5.19
======================================================================

An issue has been found in the libXpm library published by X.Org for which
we are releasing a security fix for in libXpm-3.5.19.

* CVE-2026-4367: libXpm Out-of-bounds read in xpmNextWord()

   libXpm uses a number of internal helper functions to parse the XPM file
   format.
   One of these internal functions, xpmNextString(), checks for the NULL
   terminator when looking for the end of the current string but not when
   looking for the beginning of the next string.
   A small XPM file with a malformed color table definition may cause the
   function xpmNextWord(), called from xpmParseColors() following a call
   to xpmNextString(), to start past the actual end of the file, causing
   an out-of-bound read.

   Introduced in: Unknown, prior to 3.5.5 (from Xorg 7.1)
   Fixed in: libXpm-3.5.19
   Fix: https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/5448e1bd
   Found by: Naoki Wakamatsu

comment:4 by Douglas R. Reno, 5 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-060 issued.

Note: See TracTickets for help on using tickets.