Alerts This Week
Warning Icon 1 745
Alerts This Week
Warning Icon 1 745

Fedora 43 thorvg Critical Denial of Service Resolution 2026-2641c0a950

fedora
Calendar Grey June 22, 2026
Dist Fedora Esm H88
Fedora 43 releases thorvg update to 1.0.6 addressing denial of service issues. Install via dnf for security enhancements.
Update to 1.0.6

Summary

ThorVG is an open-source graphics library designed for creating vector-based

scenes and animations. It combines immense power with remarkable lightweight

efficiency, as Thor embodies a dual meaning—symbolizing both thunderous

strength and lightning-fast agility. Embracing the philosophy of simpler is

better, the ThorVG project provides intuitive, user-friendly interfaces while

maintaining a compact footprint and minimal overhead.

The following list shows primitives that are supported by ThorVG:

- Lines & Shapes: rectangles, circles, and paths with coordinate control

- Filling: solid colors, linear & radial gradients, and path clipping

- Stroking: stroke width, joins, caps, dash patterns, and trimming

- Scene Management: retainable scene graph and object transformations

- Composition: various blending and masking

- Text: unicode characters with horizontal text layout using scalable fonts (TTF)

- Images: SVG, JPG, PNG, WebP, and raw bitmaps

- Effects: blur, drop shadow, fill, tint, tritone and color replacement

- Animations: Lottie

Update Information:

Update to 1.0.6

Change Log

* Sun Jun 14 2026 Benson Muite - 1.0.6-1 - Update to 1.0.6 * Sat Feb 14 2026 Benson Muite - 1.0.1-1 - Update to 1.0.1 rhbz#2433764 * Sat Jan 17 2026 Fedora Release Engineering - 0.15.16-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Oct 24 2025 Benson Muite - 0.15.16-1 - Update to 0.15.16 * Mon Sep 1 2025 Benson Muite - 0.15.14-1 - Update to 0.15.14

References


[ 1 ] Bug #2483802 - CVE-2026-45729 thorvg: ThorVG: Denial of Service via untrusted SVG data processing [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2483802

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-2641c0a950' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: thorvg
Product: Fedora 43
Version: 1.0.6
Release: 1.fc43
Summary: Lightweight vector-based scenes and animation drawing library

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here