Skip to content

gdk-pixbuf: Security update to 2.44.6+dfsg-1 (CVE-2026-5201)#6

Open
deepin-ci-robot wants to merge 1 commit into
masterfrom
fix/CVE-2026-5201-gdk-pixbuf
Open

gdk-pixbuf: Security update to 2.44.6+dfsg-1 (CVE-2026-5201)#6
deepin-ci-robot wants to merge 1 commit into
masterfrom
fix/CVE-2026-5201-gdk-pixbuf

Conversation

@deepin-ci-robot
Copy link
Copy Markdown
Contributor

Security Update

  • CVE: CVE-2026-5201
  • Package: gdk-pixbuf
  • Target Version: 2.44.6+dfsg-1

Description

Fix CVE-2026-5201: JPEG loader heap buffer overflow via improper validation of color component counts.

Source

Changes

This update brings gdk-pixbuf to version 2.44.6+dfsg-1 which contains the security fix for CVE-2026-5201.

Testing

  • Build verification recommended
  • Verify JPEG loading functionality

@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign goldendeng for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions
Copy link
Copy Markdown

ghost commented Apr 14, 2026

TAG Bot

TAG: 2.42.12+dfsg-5deepin1
EXISTED: no
DISTRIBUTION: unstable

@Zeno-sole
Copy link
Copy Markdown

/hold

…ponent counts in JPEG loader

Upstream commit: 6cce9311e (jpeg: Reject unsupported number of components)
@deepin-ci-robot deepin-ci-robot force-pushed the fix/CVE-2026-5201-gdk-pixbuf branch from df2b42e to 399b6f0 Compare April 15, 2026 07:22
@deepin-ci-robot
Copy link
Copy Markdown
Contributor Author

/hold
因为该quilt包的上游版本号变更,详情见: deepin-community/infra-settings#134

@deepin-community-ci-bot
Copy link
Copy Markdown

TAG Bot

New tag: 2.42.12+dfsg-5deepin1
DISTRIBUTION: unstable
Suggest: synchronizing this PR through rebase #8

Comment thread gdk-pixbuf/io-jpeg.c
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants