Opened 5 months ago
Closed 4 months ago
#23177 closed enhancement (fixed)
lcms2-2.19
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
This was reported to oss-security on 4/17/26: https://www.openwall.com/lists/oss-security/2026/04/17/16
Timeline
--------
2010-10 CubeSize() check-after-multiply pattern introduced.
2026-02-19 Fix 1: da6110b.
2026-03-12 Fix 2: e0641b1.
2026-04-13 GHSA-4xp6-rcgg-m9qq filed (private advisory).
2026-04-14 MITRE CVE request filed (CVE Request 2025002).
Submitted with the evidence that existed at the time.
2026-04-16 Asked the maintainer on the GHSA whether he'd triage,
told him I'd publish otherwise.
2026-04-17 GHSA closed without engagement. Public disclosure
This is an odd one since the changes are in upstream, but upstream didn't disclose the issue or respond to it. I'll attach a patch that fixes it.
Attachments (1)
Change History (5)
by , 5 months ago
| Attachment: | lcms2-2.18-security_fix-1.patch added |
|---|
comment:1 by , 5 months ago
| Summary: | lcms2 CVE-2026-41254 → lcms2-2.19 |
|---|
comment:2 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 5 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Note:
See TracTickets
for help on using tickets.

Fixed at acc145cdc2. Leaving open for SA.