﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	version	severity	resolution	keywords	cc
23177	lcms2-2.19	Joe Locash	SecurityAdvisory	"This was reported to oss-security on 4/17/26: https://www.openwall.com/lists/oss-security/2026/04/17/16


{{{
Timeline
--------

  2010-10      CubeSize() check-after-multiply pattern introduced.
  2026-02-19   Fix 1: da6110b.
  2026-03-12   Fix 2: e0641b1.
  2026-04-13   GHSA-4xp6-rcgg-m9qq filed (private advisory).
  2026-04-14   MITRE CVE request filed (CVE Request 2025002).
                Submitted with the evidence that existed at the time.
  2026-04-16   Asked the maintainer on the GHSA whether he'd triage,
               told him I'd publish otherwise.
  2026-04-17   GHSA closed without engagement. Public disclosure
}}}


This is an odd one since the changes are in upstream, but upstream didn't disclose the issue or respond to it. I'll attach a patch that fixes it.
"	enhancement	closed	elevated	13.1	BOOK	git	medium	fixed		
