security advisorydenial of servicebuffer overflow Several vulnerabilities were discovered in libstb, single-file image and audio processing libraries for C/C++. CVE-2021-28021 Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h. Can be exploited with a crafted JPEG file.. Debian LTS Advisory DLA-4493-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Abhijith PA February 26, 2026 https://wiki.debian.org/LTS Package : libstb Version : 0.0~git20200713.b42009b+ds-1+deb11u1 CVE ID : CVE-2021-28021 CVE-2021-37789 CVE-2021-42715 CVE-2022-28041 CVE-2022-28042 Several vulnerabilities were discovered in libstb, single-file image and audio processing libraries for C/C++. CVE-2021-28021 Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h. Can be exploited with a crafted JPEG file. CVE-2021-37789 a heap-based buffer over in stbi__jpeg_load, leading to Information Disclosure or Denial of Service. CVE-2021-42715 The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files. CVE-2022-28041 an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. CVE-2022-28042 a heap-based use-after-free via the function stbi__jpeg_huff_decode. For Debian 11 bullseye, these problems have been fixed in version 0.0~git20200713.b42009b+ds-1+deb11u1. We recommend that you upgrade your libstb packages. For the detailed security status of libstb please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/libstb Further information about Debian LTS security advisories, how to apply these updates to your system and frequently askedquestions can be found at: https://wiki.debian.org/LTS . Critical vulnerabilities found in libstb affect Debian LTS; necessary updates and patches available to mitigate risks.. Debian LTS, libstb vulnerabilities, buffer overflow, denial of service. . Severity: Important. LinuxSecurity.com Team
Feb 26, 2026 •Important Debian LTS