Описание
Security update for lcms2
This update for lcms2 fixes the following issue:
- CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994).
Список пакетов
Container suse/kiosk/firefox-esr:latest
liblcms2-2-2.15-150600.3.6.1
Container suse/kiosk/xorg-client:latest
liblcms2-2-2.15-150600.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
liblcms2-2-2.15-150600.3.6.1
liblcms2-devel-2.15-150600.3.6.1
SUSE Linux Enterprise Module for Package Hub 15 SP7
liblcms2-2-32bit-2.15-150600.3.6.1
Ссылки
- Link for SUSE-SU-2026:4205-1
- E-Mail link for SUSE-SU-2026:4205-1
- SUSE Security Ratings
- SUSE Bug 1264994
- SUSE CVE CVE-2026-41254 page
Описание
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Затронутые продукты
Container suse/kiosk/firefox-esr:latest:liblcms2-2-2.15-150600.3.6.1
Container suse/kiosk/xorg-client:latest:liblcms2-2-2.15-150600.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:liblcms2-2-2.15-150600.3.6.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:liblcms2-devel-2.15-150600.3.6.1
Ссылки
- CVE-2026-41254
- SUSE Bug 1264994
- SUSE Bug 1272458