[ubuntu/resolute-security] librsvg 2.61.3+dfsg-3ubuntu0.1 (Accepted)

John Breton john.breton at canonical.com
Tue Oct 6 17:04:04 UTC 2026


librsvg (2.61.3+dfsg-3ubuntu0.1) resolute-security; urgency=medium

  * SECURITY UPDATE: use-after-free
    - debian/patches/CVE-2026-96889.patch: (#1241): Fix use-after-free with
      duplicate XML entities in rsvg/src/xml/mod.rs, rsvg/src/xml/xml2_load.rs.
    - CVE-2026-96889

Date: 2026-10-05 20:32:33.962882+00:00
Changed-By: Isabel Garcia <isabel.garcia at canonical.com>
Signed-By: John Breton <john.breton at canonical.com>
https://launchpad.net/ubuntu/+source/librsvg/2.61.3+dfsg-3ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list