Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 595
Alerts This Week
Warning Icon 1 595

Ubuntu 26.04 LTS rlottie Critical Denial of Service USN-8559-1

ubuntu
Calendar Grey July 20, 2026
Scroller Ubuntu
Multiple issues in rlottie affect different Ubuntu versions, leading to denial of service and potential code execution risks. Update required.
rlottie could be made to crash if it received specially crafted input.

Summary

rlottie could be made to crash if it received specially crafted input.

Software Description:

- rlottie: library for rendering vector based animations and art

Details:

It was discovered that rlottie incorrectly handled certain shift

operations. An attacker could possibly use this issue to cause rlottie

to read out of bounds, resulting in a denial of service or exposing

sensitive information. (CVE-2026-10305)

It was discovered that rlottie did not properly limit recursion when

processing certain Lottie animations. An attacker could possibly use

this issue to cause rlottie to crash, resulting in a denial of service.

(CVE-2026-47306)

It was discovered that rlottie incorrectly handled certain span

coordinates. An attacker could possibly use this issue to cause a

stack-based buffer overflow, resulting in a denial of service or

possibly the execution of arbitrary code. (CVE-2026-47318)

It was discovered that rlottie incorrectly handled certain path data.

An attacker could possibly u...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  librlottie0-1                   0.1+dfsg-4.3ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 24.04 LTS
  librlottie0-1                   0.1+dfsg-4ubuntu1.1+esm1
                                  Available with Ubuntu Pro

Ubuntu 22.04 LTS
  librlottie0-1                   0.1+dfsg-2ubuntu0.2+esm1
                                  Available with Ubuntu Pro

Ubuntu 20.04 LTS
  librlottie0-1                   0~git20200305.a717479+dfsg-1ubuntu0.1~esm3
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8559-1

CVE-2026-10305, CVE-2026-47306, CVE-2026-47318, CVE-2026-47319,

CVE-2026-47320, CVE-2026-8916

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8559-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.