#1144473 rlottie: CVE-2026-19588

Package:
src:rlottie
Source:
src:rlottie
Submitter:
Salvatore Bonaccorso
Date:
2026-09-02 10:53:06 UTC
Severity:
normal
Tags:
#1144473#5
Date:
2026-08-15 14:44:41 UTC
From:
To:
Hi,

The following vulnerability was published for rlottie.

CVE-2026-19588[0]:
| Integer Overflow to Buffer Overflow vulnerability in Samsung Open
| Source rlottie allows Overflow Buffers.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19588
https://www.cve.org/CVERecord?id=CVE-2026-19588
[1] https://github.com/Samsung/rlottie/pull/600
[2] https://github.com/Samsung/rlottie/commit/27f2f23ece8a98f3e0a870e2c125faaac37e8904

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144473#10
Date:
2026-09-02 10:43:52 UTC
From:
To:
Hello,

Bug #1144473 in rlottie reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/rlottie/-/commit/7e33a8adaa4e61c90e1ee8573f2dd665b0083291
------------------------------------------------------------------------
Apply reported security fixes

Closes: #1143933, #1144473, #1144646
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144473