[Git][security-tracker-team/security-tracker][master] more libskia references for chromium issues

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 4 16:11:08 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
278e8d19 by Moritz Muehlenhoff at 2026-09-04T17:10:45+02:00
more libskia references for chromium issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -182,6 +182,7 @@ CVE-2026-85050 (Out of bounds write in WebGL in Google Chrome on on Android prio
 	- chromium <unfixed>
 CVE-2026-85049 (Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed ...)
 	- chromium <unfixed>
+	- libskia <unfixed>
 CVE-2026-85048 (Use after free in Compositing in Google Chrome prior to 152.0.7977.82  ...)
 	- chromium <unfixed>
 CVE-2026-85047 (Improper input validation in Transactions Platform in Google Chrome on ...)
@@ -2221,6 +2222,7 @@ CVE-2026-84354 (Incorrect authorization in FileSystem in Google Chrome prior to
 CVE-2026-84359 (Information leak in Skia in Google Chrome prior to 152.0.7977.75 allow ...)
 	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
+	- libskia <unfixed>
 CVE-2026-84357 (Improper input validation in Omnibox in Google Chrome prior to 152.0.7 ...)
 	{DSA-6482-1}
 	- chromium 152.0.7977.75-1
@@ -8848,6 +8850,7 @@ CVE-2026-79144 (Information leak in Skia in Google Chrome prior to 152.0.7977.65
 	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-79143 (Incorrect authorization in FileSystem in Google Chrome prior to 152.0. ...)
 	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
@@ -9269,6 +9272,7 @@ CVE-2026-79020 (Out of bounds read in Skia in Google Chrome prior to 152.0.7977.
 	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-79019 (Out of bounds write in ANGLE in Google Chrome on on Windows prior to 1 ...)
 	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
@@ -9465,6 +9469,7 @@ CVE-2026-78958 (Uninitialized resource in Skia in Google Chrome prior to 152.0.7
 	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	NOTE: Not an issue in Skia, but Chromium's use of Skia
 CVE-2026-78957 (Information leak in Mobile in Google Chrome on on iOS prior to 152.0.7 ...)
 	{DSA-6482-1}
 	- chromium 152.0.7977.64-1
@@ -18182,6 +18187,7 @@ CVE-2026-76041 (Information leak in Skia in Google Chrome prior to 151.0.7922.16
 	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-76047 (Type confusion in V8 in Google Chrome prior to 151.0.7922.169 allowed  ...)
 	{DSA-6455-1 DLA-4749-1}
 	- chromium 151.0.7922.169-1
@@ -35126,6 +35132,7 @@ CVE-2026-19154 (Use after free in Skia in Google Chrome on Android prior to 151.
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-19157 (Out of bounds write in ANGLE in Google Chrome on Android prior to 151. ...)
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
@@ -35226,10 +35233,12 @@ CVE-2026-19160 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.1
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-19161 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 all ...)
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-19162 (Out of bounds write in V8 in Google Chrome prior to 151.0.7922.109 all ...)
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
@@ -35262,6 +35271,7 @@ CVE-2026-19173 (Out of bounds write in Skia in Google Chrome prior to 151.0.7922
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-19174 (Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowe ...)
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
@@ -35274,6 +35284,7 @@ CVE-2026-19176 (Use after free in Skia in Google Chrome prior to 151.0.7922.109
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-19177 (Insufficient validation of untrusted input in UI in Google Chrome prio ...)
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
@@ -40367,6 +40378,7 @@ CVE-2026-17992 (Uninitialized Use in Skia in Google Chrome on Windows prior to 1
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-17991 (Insufficient validation of untrusted input in AI in Google Chrome prio ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
@@ -40679,6 +40691,7 @@ CVE-2026-17914 (Side-channel information leakage in Skia in Google Chrome prior
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-17913 (Inappropriate implementation in Chrome for iOS in Google Chrome on iOS ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
@@ -41251,6 +41264,7 @@ CVE-2026-17771 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.7
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-17770 (Out of bounds read in Media in Google Chrome on Mac prior to 151.0.792 ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
@@ -41307,6 +41321,7 @@ CVE-2026-17757 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.7
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-17756 (Insufficient policy enforcement in Presentation in Google Chrome prior ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
@@ -41355,6 +41370,7 @@ CVE-2026-17745 (Out of bounds read in Skia in Google Chrome prior to 151.0.7922.
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-17744 (Inappropriate implementation in File Input in Google Chrome on Linux p ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
@@ -41487,6 +41503,7 @@ CVE-2026-17712 (Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allo
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-17711 (Race in Downloads in Google Chrome on Mac prior to 151.0.7922.72 allow ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
@@ -41527,6 +41544,7 @@ CVE-2026-17702 (Inappropriate implementation in Skia in Google Chrome prior to 1
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-17701 (Insufficient validation of untrusted input in ANGLE in Google Chrome o ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
@@ -41723,6 +41741,7 @@ CVE-2026-17653 (Use after free in Skia in Google Chrome prior to 151.0.7922.72 a
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-17652 (Use after free in Views in Google Chrome prior to 151.0.7922.72 allowe ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
@@ -50824,6 +50843,7 @@ CVE-2026-16417 (Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.1
 	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-16418 (Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 a ...)
 	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
@@ -58804,6 +58824,7 @@ CVE-2026-15774 (Use after free in Skia in Google Chrome prior to 150.0.7871.125
 	{DSA-6390-1 DLA-4687-1}
 	- chromium 150.0.7871.124-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-15773 (Use after free in Core in Google Chrome on Windows prior to 150.0.7871 ...)
 	{DSA-6390-1 DLA-4687-1}
 	- chromium 150.0.7871.124-1
@@ -58836,6 +58857,7 @@ CVE-2026-15766 (Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.1
 	{DSA-6390-1 DLA-4687-1}
 	- chromium 150.0.7871.124-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
+	- libskia <unfixed>
 CVE-2026-15765 (Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allow ...)
 	{DSA-6390-1 DLA-4687-1}
 	- chromium 150.0.7871.124-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/278e8d1919a9b56abbe559178884e356220c4d4c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/278e8d1919a9b56abbe559178884e356220c4d4c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/7b3c97f5/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list