#1143933 rlottie: CVE-2026-15551

Package:
src:rlottie
Source:
src:rlottie
Submitter:
Moritz Mühlenhoff
Date:
2026-09-01 12:17:02 UTC
Severity:
normal
Tags:
#1143933#5
Date:
2026-08-08 15:52:02 UTC
From:
To:
Hi,

The following vulnerability was published for rlottie.

CVE-2026-15551[0]:
| Integer overflow or wraparound vulnerability in Samsung Open Source
| rlottie allows Overflow Buffers.  This issue affects .

https://github.com/Samsung/rlottie/pull/595

Fixed by: https://github.com/Samsung/rlottie/commit/f487eff2f8086b84ae1c7faa0418abec909e874b


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-15551
https://www.cve.org/CVERecord?id=CVE-2026-15551

Please adjust the affected versions in the BTS as needed.

#1143933#34
Date:
2026-09-01 12:04:03 UTC
From:
To:
Hello,

Bug #1143933 in rlottie reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/rlottie/-/commit/7e33a8adaa4e61c90e1ee8573f2dd665b0083291
------------------------------------------------------------------------
Apply reported security fixes

Closes: #1143933, #1144473, #1144646
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1143933