[Git][security-tracker-team/security-tracker][master] rlottie/libstb n/a

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 6 20:20:57 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
de8af151 by Moritz Muehlenhoff at 2026-09-06T21:20:45+02:00
rlottie/libstb n/a

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2205,7 +2205,12 @@ CVE-2026-62906 (Improper neutralization of special elements in data query logic
 CVE-2026-53728 (Medplum is a developer platform that enables development of healthcare ...)
 	NOT-FOR-US: Medplum
 CVE-2026-49509 (Out-of-bounds read vulnerability in Samsung Opensource Escargot allows ...)
-	TODO: check
+	- rlottie <not-affected> (rlottie in Debian uses the packaged libstb)
+	NOTE: rlottie as packaged in Debian uses the system-copy of libstb
+	NOTE: The fix that was made for the vendored copy of rlottie is
+	NOTE: https://github.com/Samsung/rlottie/commit/25648aef19187b3f87f4d9420b8d761453ad4630
+	NOTE: But the equivalent patch in src:libstb was already made years ago in
+	NOTE: https://github.com/nothings/stb/commit/5ba0baaa269b3fd681828e0e3b3ac0f1472eaf40
 CVE-2026-45200 (Software installed and run as a non-privileged user may conduct improp ...)
 	NOT-FOR-US: Imagination Technologies
 CVE-2026-45197 (Kernel software installed and running inside a Guest VM may post impro ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de8af1517d3cdc4e68d2b51546df0c00c13b96de

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de8af1517d3cdc4e68d2b51546df0c00c13b96de
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/ba7f51c9/attachment.htm>


More information about the debian-security-tracker-commits mailing list