Opened 5 months ago

Closed 4 months ago

#23177 closed enhancement (fixed)

lcms2-2.19

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

This was reported to oss-security on 4/17/26: ​https://www.openwall.com/lists/oss-security/2026/04/17/16

Timeline
--------

  2010-10      CubeSize() check-after-multiply pattern introduced.
  2026-02-19   Fix 1: da6110b.
  2026-03-12   Fix 2: e0641b1.
  2026-04-13   GHSA-4xp6-rcgg-m9qq filed (private advisory).
  2026-04-14   MITRE CVE request filed (CVE Request 2025002).
                Submitted with the evidence that existed at the time.
  2026-04-16   Asked the maintainer on the GHSA whether he'd triage,
               told him I'd publish otherwise.
  2026-04-17   GHSA closed without engagement. Public disclosure

This is an odd one since the changes are in upstream, but upstream didn't disclose the issue or respond to it. I'll attach a patch that fixes it.

Attachments (1)

lcms2-2.18-security_fix-1.patch​ (1.8 KB ) - added by Joe Locash 5 months ago.

Download all attachments as: .zip

Change History (5)

by Joe Locash, 5 months ago

comment:1 by Joe Locash, 5 months ago

Summary: lcms2 CVE-2026-41254 → lcms2-2.19

comment:2 by Joe Locash, 5 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 5 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new
-----------------------
2.19 Featured release
-----------------------
CMake build system. Thanks to Vlad Erium for the initial implementation and kmilos for improvements. 
Large files support to use profiles up to 4Gb
Black point compensation works on multi-channel profiles
Added more test platforms/architectures in GitHub tests, Cygwin and MSYS are now fully checked.
jpgicc banner is not shown on normal operation, only when help is requested.
Added a way to access internal transform pipelines. For read only.
Add a way to retrieve the CMM signature
Added extra checks on postscript undocumented functions
Added guard on integer overflow when reading .cube files
Added unneeded checks as a try to get rid of spam reports about "vulnerabilities" that are not real.
Utility program names generated by Visual Studio 2026 are now same as all other platforms.
Creating an output profile by cmsTransform2DeviceLink does not propagate correctly the colorant table. Fixed.
Added some profile class definitions from iccMAX
Deprecated uint16 and uint32 types removed from tifdiff

Fixed at acc145cdc2. Leaving open for SA.

comment:4 by Douglas R. Reno, 4 months ago

Resolution: → fixed
Status: new → closed

SA-13.0-080 issued

Note: See TracTickets for help on using tickets.