Explore top 10 tips to secure your open-source projects now. Read More
×
rlottie could be made to crash if it received specially crafted input.
Software Description:
- rlottie: library for rendering vector based animations and art
Details:
It was discovered that rlottie incorrectly handled certain shift
operations. An attacker could possibly use this issue to cause rlottie
to read out of bounds, resulting in a denial of service or exposing
sensitive information. (CVE-2026-10305)
It was discovered that rlottie did not properly limit recursion when
processing certain Lottie animations. An attacker could possibly use
this issue to cause rlottie to crash, resulting in a denial of service.
(CVE-2026-47306)
It was discovered that rlottie incorrectly handled certain span
coordinates. An attacker could possibly use this issue to cause a
stack-based buffer overflow, resulting in a denial of service or
possibly the execution of arbitrary code. (CVE-2026-47318)
It was discovered that rlottie incorrectly handled certain path data.
An attacker could possibly u...
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
librlottie0-1 0.1+dfsg-4.3ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 24.04 LTS
librlottie0-1 0.1+dfsg-4ubuntu1.1+esm1
Available with Ubuntu Pro
Ubuntu 22.04 LTS
librlottie0-1 0.1+dfsg-2ubuntu0.2+esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
librlottie0-1 0~git20200305.a717479+dfsg-1ubuntu0.1~esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.https://ubuntu.com/security/notices/USN-8559-1
CVE-2026-10305, CVE-2026-47306, CVE-2026-47318, CVE-2026-47319,
CVE-2026-47320, CVE-2026-8916
Get the latest Linux and open source security news straight to your inbox.