[Git][security-tracker-team/security-tracker][master] mark three CVEs for Skia as specific to how Chromium uses Skia, not Skia itself

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 6 12:08:09 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
612b907b by Moritz Muehlenhoff at 2026-09-06T13:07:34+02:00
mark three CVEs for Skia as specific to how Chromium uses Skia, not Skia itself

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11192,7 +11192,7 @@ CVE-2026-79020 (Out of bounds read in Skia in Google Chrome prior to 152.0.7977.
 	{DSA-6482-1 DLA-4771-1}
 	- chromium 152.0.7977.64-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
-	- libskia <unfixed>
+	NOTE: Not an issue in Skia, but Chromium's use of Skia
 CVE-2026-79019 (Out of bounds write in ANGLE in Google Chrome on on Windows prior to 1 ...)
 	{DSA-6482-1 DLA-4771-1}
 	- chromium 152.0.7977.64-1
@@ -37210,7 +37210,7 @@ CVE-2026-19173 (Out of bounds write in Skia in Google Chrome prior to 151.0.7922
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
-	- libskia <unfixed>
+	NOTE: Not an issue in Skia, but Chromium's use of Skia
 CVE-2026-19174 (Integer overflow in V8 in Google Chrome prior to 151.0.7922.109 allowe ...)
 	{DSA-6422-1 DLA-4728-1}
 	- chromium 151.0.7922.108-1
@@ -43210,7 +43210,7 @@ CVE-2026-17771 (Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.7
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
-	- libskia <unfixed>
+	NOTE: Not an issue in Skia, but Chromium's use of Skia
 CVE-2026-17770 (Out of bounds read in Media in Google Chrome on Mac prior to 151.0.792 ...)
 	{DSA-6408-1 DLA-4710-1}
 	- chromium 151.0.7922.71-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/612b907bf7f2e56f0644bf0e8325ef296d0ab596

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/612b907bf7f2e56f0644bf0e8325ef296d0ab596
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/9fcdf94a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list