[Git][security-tracker-team/security-tracker][master] Track fixes for libskia via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 2 20:25:17 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6fa211bb by Salvatore Bonaccorso at 2026-07-02T21:24:46+02:00
Track fixes for libskia via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1704,7 +1704,7 @@ CVE-2026-13780 (Insufficient validation of untrusted input in ANGLE in Google Ch
 CVE-2026-13781 (Insufficient validation of untrusted input in Skia in Google Chrome pr ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-	- libskia <unfixed>
+	- libskia 146.20260602~git.3476902+dfsg-1
 CVE-2026-13782 (Use after free in Browser in Google Chrome prior to 150.0.7871.47 allo ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
@@ -1822,7 +1822,7 @@ CVE-2026-13819 (Out of bounds read in ANGLE in Google Chrome on Mac prior to 150
 CVE-2026-13820 (Out of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871 ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-	- libskia <unfixed>
+	- libskia 146.20260602~git.3476902+dfsg-1
 CVE-2026-13821 (Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allow ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
@@ -1886,7 +1886,7 @@ CVE-2026-13840 (Insufficient policy enforcement in Canvas in Google Chrome prior
 CVE-2026-13841 (Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allow ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-	- libskia <unfixed>
+	- libskia 146.20260602~git.3476902+dfsg-1
 CVE-2026-13842 (Inappropriate implementation in Chrome for iOS in Google Chrome on iOS ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
@@ -2020,7 +2020,7 @@ CVE-2026-13884 (Integer overflow in Chromecast in Google Chrome prior to 150.0.7
 CVE-2026-13885 (Use after free in Skia in Google Chrome on Android prior to 150.0.7871 ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-	- libskia <unfixed>
+	- libskia 146.20260602~git.3476902+dfsg-1
 CVE-2026-13886 (Insufficient policy enforcement in Isolated Web Apps in Google Chrome  ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
@@ -2279,7 +2279,7 @@ CVE-2026-13970 (Uninitialized Use in Media in Google Chrome prior to 150.0.7871.
 CVE-2026-13971 (Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allo ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-	- libskia <unfixed>
+	- libskia 146.20260602~git.3476902+dfsg-1
 CVE-2026-13972 (Inappropriate implementation in Paint in Google Chrome prior to 150.0. ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fa211bbe92ee80e035cf178b0ebd75abb0edea5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6fa211bbe92ee80e035cf178b0ebd75abb0edea5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260702/478d6eb7/attachment.htm>


More information about the debian-security-tracker-commits mailing list