#1144646 rlottie: CVE-2026-19517 CVE-2026-19518

Package:
src:rlottie
Source:
src:rlottie
Submitter:
Salvatore Bonaccorso
Date:
2026-09-01 12:17:03 UTC
Severity:
normal
Tags:
#1144646#5
Date:
2026-08-17 15:03:44 UTC
From:
To:
Hi,

The following vulnerabilities were published for rlottie.

CVE-2026-19517[0]:
| Improper Validation of Specified Quantity in Input and Allocation of
| Resources Without Limits or Throttling vulnerability in Samsung Open
| Source rlottie allows Excessive Allocation.


CVE-2026-19518[1]:
| Improper Validation of Specified Quantity in Input vulnerability in
| Samsung Open Source rlottie allows Input Data Manipulation.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19517
https://www.cve.org/CVERecord?id=CVE-2026-19517
[1] https://security-tracker.debian.org/tracker/CVE-2026-19518
https://www.cve.org/CVERecord?id=CVE-2026-19518
[2] https://github.com/Samsung/rlottie/pull/596
[3] https://github.com/Samsung/rlottie/commit/2cab35db755b0e39df40b679969495e90d39c578

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144646#10
Date:
2026-09-01 12:04:03 UTC
From:
To:
Hello,

Bug #1144646 in rlottie reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/rlottie/-/commit/7e33a8adaa4e61c90e1ee8573f2dd665b0083291
------------------------------------------------------------------------
Apply reported security fixes

Closes: #1143933, #1144473, #1144646
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1144646