[Git][security-tracker-team/security-tracker][master] Add CVE-2026-10305/rlottie

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jun 6 09:37:04 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b2b53fda by Salvatore Bonaccorso at 2026-06-06T10:36:44+02:00
Add CVE-2026-10305/rlottie

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2022,7 +2022,9 @@ CVE-2026-10737 (The SP Project & Document Manager plugin for WordPress is vulner
 CVE-2026-10597 (OMICARD EDM developed by ITPison has a Insecure Direct Object Referenc ...)
 	NOT-FOR-US: ITPison
 CVE-2026-10305 (Out-of-bounds read vulnerability in Samsung Open Source rlottie allows ...)
-	TODO: check
+	- rlottie <unfixed>
+	NOTE: https://github.com/Samsung/rlottie/pull/587
+	NOTE: https://github.com/Samsung/rlottie/commit/b4f5101a4d1a8da60cc14cfd05608551b3448c77
 CVE-2025-71316 (SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Wi ...)
 	TODO: check
 CVE-2025-69755 (An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a re ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2b53fda674e82691853a0f0c2c7bf7c63c234a9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2b53fda674e82691853a0f0c2c7bf7c63c234a9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260606/e91f5195/attachment.htm>


More information about the debian-security-tracker-commits mailing list