Alerts This Week
Warning Icon 1 989
Alerts This Week
Warning Icon 1 989

Ubuntu 22.04 LTS Cairo Critical Denial Service Issues USN-8140-1

ubuntu
Calendar Grey April 2, 2026
Dist Ubuntu Esm H88
Multiple security issues in Cairo library on Ubuntu may result in denial of service. Update your system promptly.
Several security issues were fixed in Cairo.

Summary

Several security issues were fixed in Cairo.

Software Description:

- cairo: Cairo 2D vector graphics library performance utilities

Details:

Alberto Garcia, Francisco Oca and Suleman Ali discovered that Cairo did

not properly manage memory. An attacker could possibly use this issue to

cause Cairo to crash, resulting in a denial of service. This issue only

affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.

(CVE-2017-9814)

It was discovered that Cairo incorrectly handled certain angle values when

drawing arcs. An attacker could possibly use this issue to cause Cairo to

crash, resulting in a denial of service. (CVE-2019-6461)

It was discovered that Cairo incorrectly handled certain calculations when

drawing arcs. An attacker could possibly use this issue to cause Cairo to

consume resources, resulting in a denial of service. This issue only

affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS and Ubuntu 22.04 LTS.

(CVE-2019-6462)

Stephan Bergmann discovered that Cairo incorr...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
  cairo-perf-utils                1.16.0-5ubuntu2.1
  libcairo2                       1.16.0-5ubuntu2.1

Ubuntu 20.04 LTS
  cairo-perf-utils                1.16.0-4ubuntu1+esm1
                                  Available with Ubuntu Pro
  libcairo2                       1.16.0-4ubuntu1+esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  cairo-perf-utils                1.15.10-2ubuntu0.1+esm1
                                  Available with Ubuntu Pro
  libcairo2                       1.15.10-2ubuntu0.1+esm1
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  cairo-perf-utils                1.14.6-1ubuntu0.1~esm2
                                  Available with Ubuntu Pro
  libcairo2                       1.14.6-1ubuntu0.1~esm2
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8140-1

CVE-2017-9814, CVE-2019-6461, CVE-2019-6462, CVE-2020-35492

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8140-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here