Описание
Security update for lcms2
This update for lcms2 fixes the following issues
- CVE-2026-41254: integer overflow in CubeSize in cmslut.c (bsc#1264994).
- CVE-2026-42798: integer overflow in ParseCube in cmscgats.c (bsc#1263703).
Список пакетов
openSUSE Leap 16.0
lcms2-2.16-160000.4.1
liblcms2-2-2.16-160000.4.1
liblcms2-devel-2.16-160000.4.1
liblcms2-doc-2.16-160000.4.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1263703
- SUSE Bug 1264994
- SUSE CVE CVE-2026-41254 page
- SUSE CVE CVE-2026-42798 page
Описание
Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication.
Затронутые продукты
openSUSE Leap 16.0:lcms2-2.16-160000.4.1
openSUSE Leap 16.0:liblcms2-2-2.16-160000.4.1
openSUSE Leap 16.0:liblcms2-devel-2.16-160000.4.1
openSUSE Leap 16.0:liblcms2-doc-2.16-160000.4.1
Ссылки
- CVE-2026-41254
- SUSE Bug 1264994
Описание
Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c.
Затронутые продукты
openSUSE Leap 16.0:lcms2-2.16-160000.4.1
openSUSE Leap 16.0:liblcms2-2-2.16-160000.4.1
openSUSE Leap 16.0:liblcms2-devel-2.16-160000.4.1
openSUSE Leap 16.0:liblcms2-doc-2.16-160000.4.1
Ссылки
- CVE-2026-42798
- SUSE Bug 1263703