#1146703 dia: CVE-2026-77658

Package:
src:dia
Source:
src:dia
Submitter:
Moritz Mühlenhoff
Date:
2026-09-04 17:39:02 UTC
Severity:
normal
Tags:
#1146703#5
Date:
2026-09-04 16:08:02 UTC
From:
To:
Hi,

The following vulnerability was published for dia.

CVE-2026-77658[0]:
| A stack-based buffer overflow vulnerability exists in the Dia
| diagram editor when processing Network Bus objects from Dia XML
| project files.  In objects/network/bus.c, bus_load() reads the
| number of bus handles from the file attribute "bus_handles" using
| attribute_num_data() without validating an upper bound:
| bus->num_handles = attribute_num_data(attr);  When a bus handle is
| subsequently moved, bus_handle_moved() allocates two temporary
| arrays on the stack:      parallel = (real *)g_alloca(num_handles *
| sizeof(real));     perp = (real *)g_alloca(num_handles *
| sizeof(real));  Because num_handles is fully attacker-controlled via
| the project file, sufficiently large values (for example 262144 or
| higher) cause g_alloca() to consume more stack space than the
| default thread stack limit (typically 8 MB on Linux), resulting in
| stack overflow, SIGSEGV, and potential stack frame / return-address
| corruption.  An attacker can embed a Bus object with an excessive
| bus_handles count in a malicious .dia file. Exploitation requires
| the victim to open the file in Dia (file dialog, command line, or
| file association) and trigger handle manipulation (moving a bus
| handle), which exercises the vulnerable code path.  The identical
| g_alloca pattern is present in objects/Misc/tree.c (copied from
| bus.c) and is likely vulnerable to the same class of attack via Tree
| objects.  Affected versions: Dia 0.98.0 and earlier versions
| containing this code; issue confirmed on upstream master as of
| 2026-08-21. Upstream report:
| https://gitlab.gnome.org/GNOME/dia/-/issues/581

https://gitlab.gnome.org/GNOME/dia/-/issues/581


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-77658
https://www.cve.org/CVERecord?id=CVE-2026-77658

Please adjust the affected versions in the BTS as needed.