Fix access/use of uninitialized memory in stb_image. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-651e3129a9 2026-04-18 01:08:05.671404+00:00 -------------------------------------------------------------------------------- Name : stb Product : Fedora 42 Version : 0^20260313git904aa67 Release : 2.fc42 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. -------------------------------------------------------------------------------- Update Information: Fix access/use of uninitialized memory in stb_image -------------------------------------------------------------------------------- ChangeLog: * Wed Apr 8 2026 Benjamin A. Beasley - 0^20260313git904aa67-2 - Fix access/use of uninitialized memory in stb_image - This was undefined behavior, and could leak security-relevant information from other data structures. See https://github.com/nothings/stb/issues/1929. -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-651e3129a9' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Patch two newly-reported memory-safety bugs in stb_image: https://github.com/nothings/stb/issues/1860 . -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-7ea43a29f2 2025-12-04 01:02:25.792107+00:00 -------------------------------------------------------------------------------- Name : stb Product : Fedora 42 Version : 0^20251025gitf1c79c0 Release : 2.fc42 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. -------------------------------------------------------------------------------- Update Information: Patch two newly-reported memory-safety bugs in stb_image: https://github.com/nothings/stb/issues/1860 https://github.com/nothings/stb/issues/1861 -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 25 2025 Benjamin A. Beasley - 0^20251025gitf1c79c0-2 - Patch two newly-reported memory-safety bugs in stb_image - https://github.com/nothings/stb/issues/1860 - https://github.com/nothings/stb/issues/1861 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-7ea43a29f2' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Patch two newly-reported memory-safety bugs in stb_image: https://github.com/nothings/stb/issues/1860 https://github.com/nothings/stb/issues/1861. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-55bbd18c79 2025-12-04 00:51:14.440659+00:00 -------------------------------------------------------------------------------- Name : stb Product : Fedora 43 Version : 0^20251025gitf1c79c0 Release : 2.fc43 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. -------------------------------------------------------------------------------- Update Information: Patch two newly-reported memory-safety bugs in stb_image: https://github.com/nothings/stb/issues/1860 https://github.com/nothings/stb/issues/1861 -------------------------------------------------------------------------------- ChangeLog: * Tue Nov 25 2025 Benjamin A. Beasley - 0^20251025gitf1c79c0-2 - Patch two newly-reported memory-safety bugs in stb_image - https://github.com/nothings/stb/issues/1860 - https://github.com/nothings/stb/issues/1861 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-55bbd18c79' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Add another patch for the root cause of CVE-2021-45340. We already have a patch for CVE-2021-45340, but adding this new patch may prevent a related, unproven exploit as described in https://github.com/nothings/stb/pull/1454#issuecomment-2581308033.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-6a64d3b2fc 2025-01-19 01:25:41.141784+00:00 -------------------------------------------------------------------------------- Name : stb Product : Fedora 41 Version : 0^20241002git31707d1 Release : 5.fc41 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. -------------------------------------------------------------------------------- Update Information: Add another patch for the root cause of CVE-2021-45340. We already have a patch for CVE-2021-45340, but adding this new patch may prevent a related, unproven exploit as described in https://github.com/nothings/stb/pull/1454#issuecomment-2581308033. -------------------------------------------------------------------------------- ChangeLog: * Thu Jan 9 2025 Benjamin A. Beasley - 0^20241002git31707d1-5 - Patch root cause of CVE-2021-45340 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-6a64d3b2fc' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Multiple vulnerabilities have been discovered in stb, the worst of which lead to a denial of service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202409-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: stb: Multiple Vulnerabilities Date: September 22, 2024 Bugs: #818556 ID: 202409-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== Multiple vulnerabilities have been discovered in stb, the worst of which lead to a denial of service. Background ========== A set of single-file public domain (or MIT licensed) libraries for C/C++ Affected packages ================= Package Vulnerable Unaffected ------------ ------------ ------------ dev-libs/stb < 20240201 > = 20240201 Description =========== Multiple vulnerabilities have been discovered in stb. Please review the CVE identifiers referenced below for details. Impact ====== Please review the referenced CVE identifiers for details. Workaround ========== There is no known workaround at this time. Resolution ========== All stb users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-libs/stb-20240201" Note that stb is included at compile time, so all packages that depend on it should also be reinstalled. If you have app-portage/gentoolkit installed you can use: # emerge --ask --verbose $( equery depends dev-libs/stb | sed 's/^/=/' ) References ========== [ 1 ] CVE-2021-28021 https://nvd.nist.gov/vuln/detail/CVE-2021-28021 [ 2 ] CVE-2021-37789 https://nvd.nist.gov/vuln/detail/CVE-2021-37789 [ 3 ] CVE-2021-42715 https://nvd.nist.gov/vuln/detail/CVE-2021-42715 [ 4 ] CVE-2021-42716 https://nvd.nist.gov/vuln/detail/CVE-2021-42716 [ 5 ] CVE-2022-28041 https://nvd.nist.gov/vuln/detail/CVE-2022-28041 [ 6 ] CVE-2022-28042 https://nvd.nist.gov/vuln/detail/CVE-2022-28042 [ 7 ] CVE-2022-28048 https://nvd.nist.gov/vuln/detail/CVE-2022-28048 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202409-15 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to
Security fix for CVE-2023-45681 / CVE-2023-47212. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-5e5d8c2581 2024-05-11 01:36:38.084622 -------------------------------------------------------------------------------- Name : stb Product : Fedora 38 Version : 0^20240213gitae721c5 Release : 5.fc38 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2023-45681 / CVE-2023-47212 -------------------------------------------------------------------------------- ChangeLog: * Thu May 2 2024 Benjamin A. Beasley - 0^20240213gitae721c5-5 - Patch for GHSL-2023-171/CVE-2023-45681/CVE-2023-47212 * Thu May 2 2024 Benjamin A. Beasley - 0^20240213gitae721c5-4 - Fix a description to use American English orthography * Thu May 2 2024 David Abdurachmanov - 0^20240213gitae721c5-2 - Fix compile error on riscv64 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2278401 - CVE-2023-47212 stb: stb_vorbis.c comment heap-based buffer overflow vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=2278401 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-5e5d8c2581' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security fix for CVE-2022-28041, CVE-2022-28042, CVE-2022-28048. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-c8f6a39cf6 2022-05-07 04:08:14.316372 --------------------------------------------------------------------------------Name : stb Product : Fedora 36 Version : 0^20210910gitaf1a5bc Release : 0.2.fc36 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-28041, CVE-2022-28042, CVE-2022-28048 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 20 2022 Benjamin A. Beasley 0^20210910gitaf1a5bc-0.2 - Security fix for CVE-2022-28041 (fix RHBZ#2077020, fix RBHZ#2077019) * Sat Apr 16 2022 Benjamin A. Beasley 0^20210910gitaf1a5bc-0.1 - Switch to modern snapshot versioning * Sat Apr 16 2022 Benjamin A. Beasley 0-0.10 - Stop numbering patches --------------------------------------------------------------------------------References: [ 1 ] Bug #2077019 - CVE-2022-28041 stb: integer overflow in stbi__jpeg_decode_block_prog_dc() can lead to DoS https://bugzilla.redhat.com/show_bug.cgi?id=2077019 [ 2 ] Bug #2077022 - CVE-2022-28042 stb: use-after-free in stbi__jpeg_huff_decode() https://bugzilla.redhat.com/show_bug.cgi?id=2077022 [ 3 ] Bug #2077028 - CVE-2022-28048 stb: integer shift of invalid size in stbi__jpeg_decode_block_prog_ac() https://bugzilla.redhat.com/show_bug.cgi?id=2077028 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2022-c8f6a39cf6' at the command line. For more information, refer to the dnf documentation availableat https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Security fix for CVE-2022-28041, CVE-2022-28042, CVE-2022-28048. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2022-fe84314a8e 2022-04-28 05:50:06.248770 --------------------------------------------------------------------------------Name : stb Product : Fedora 35 Version : 0^20210910gitaf1a5bc Release : 0.2.fc35 URL : https://github.com/nothings/stb Summary : Single-file public domain libraries for C/C++ Description : Single-file public domain libraries for C/C++. --------------------------------------------------------------------------------Update Information: Security fix for CVE-2022-28041, CVE-2022-28042, CVE-2022-28048 --------------------------------------------------------------------------------ChangeLog: * Wed Apr 20 2022 Benjamin A. Beasley 0^20210910gitaf1a5bc-0.2 - Security fix for CVE-2022-28041 (fix RHBZ#2077020, fix RBHZ#2077019) * Wed Apr 20 2022 Benjamin A. Beasley 0^20210910gitaf1a5bc-0.1 - Switch to modern snapshot versioning * Wed Apr 20 2022 Benjamin A. Beasley 0-0.9 - Stop numbering patches * Wed Apr 20 2022 Benjamin A. Beasley 0-0.8 - Apply a patch for warnings in stb_herringbone_wang_tile --------------------------------------------------------------------------------References: [ 1 ] Bug #2077019 - CVE-2022-28041 stb: integer overflow in stbi__jpeg_decode_block_prog_dc() can lead to DoS https://bugzilla.redhat.com/show_bug.cgi?id=2077019 [ 2 ] Bug #2077022 - CVE-2022-28042 stb: use-after-free in stbi__jpeg_huff_decode() https://bugzilla.redhat.com/show_bug.cgi?id=2077022 [ 3 ] Bug #2077028 - CVE-2022-28048 stb: integer shift of invalid size in stbi__jpeg_decode_block_prog_ac() https://bugzilla.redhat.com/show_bug.cgi?id=2077028 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2022-fe84314a8e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.