Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!

Bug 836241 (CVE-2022-27938)

Summary: dev-libs/stb: reachable assertion in stbi__create_png_image_raw
Product: Gentoo Security Reporter: John Helmert III <ajak>
Component: VulnerabilitiesAssignee: Gentoo Security <security>
Status: CONFIRMED ---    
Severity: minor CC: 3dprint, mathy, proxy-maint
Priority: Normal    
Version: unspecified   
Hardware: All   
OS: Linux   
URL: https://github.com/saitoha/libsixel/issues/163
Whiteboard: B3 [upstream]
Package list:
Runtime testing required: ---
Bug Depends on: 832049    
Bug Blocks:    

Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-27 01:12:40 UTC
CVE-2022-27938:

stb_image.h (aka the stb image loader) 2.19, as used in libsixel and other products, has a reachable assertion in stbi__create_png_image_raw.