Fedora alert FEDORA-2026-b9f00ad1b7 (vips)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 44 Update: vips-8.18.3-2.fc44 | |
| Date: | Tue, 23 Jun 2026 01:09:31 +0000 | |
| Message-ID: | <20260623010931.0B2E176571@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b9f00ad1b7 2026-06-23 01:06:46.785031+00:00 -------------------------------------------------------------------------------- Name : vips Product : Fedora 44 Version : 8.18.3 Release : 2.fc44 URL : https://www.libvips.org/ Summary : C/C++ library for processing large images Description : VIPS is an image processing library. It is good for very large images (even larger than the amount of RAM in your machine), and for working with color. This package should be installed if you want to use a program compiled against VIPS. -------------------------------------------------------------------------------- Update Information: update to v8.18.3 enable uhdr fix several security issues -------------------------------------------------------------------------------- ChangeLog: * Sat Jun 13 2026 Adam Goode <adam@spicenitz.org> - 8.18.3-2 - Upload vips v8.18.3 sources * Sat Jun 13 2026 Kleis Auke Wolthuizen <fedora@kleisauke.nl> - 8.18.3-1 - Update to 8.18.3 - Drop patches merged upstream - Build against libultrahdr (rhbz#2427101) * Sun May 31 2026 Richard Shaw <hobbes1069@gmail.com> - 8.18.0-8 - Rebuild for OpenColorIO 2.5.2. * Mon May 25 2026 Richard Shaw <hobbes1069@gmail.com> - 8.18.0-7 - Rebuild for OpenEXR 3.4.12. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2442677 - CVE-2026-3146 vips: libvips: Local denial of service due to null pointer dereference [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2442677 [ 2 ] Bug #2442681 - CVE-2026-3145 vips: libvips: Memory corruption via local manipulation [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2442681 [ 3 ] Bug #2442683 - CVE-2026-3147 vips: libvips: Heap-based buffer overflow [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2442683 [ 4 ] Bug #2443335 - CVE-2026-3282 vips: libvips unpremultiply.c vips_unpremultiply_build out-of-bounds [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2443335 [ 5 ] Bug #2443339 - CVE-2026-3284 vips: libvips extract.c vips_extract_area_build integer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2443339 [ 6 ] Bug #2443343 - CVE-2026-3283 vips: libvips extract.c vips_extract_band_build out-of-bounds [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2443343 [ 7 ] Bug #2443344 - CVE-2026-3281 vips: libvips bandrank.c vips_bandrank_build heap-based overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2443344 [ 8 ] Bug #2448617 - vips-8.18.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2448617 [ 9 ] Bug #2459221 - CVE-2026-6491 vips: heap-based buffer over-read in im_minpos_vec() in libvips/deprecated/vips7compat.c [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2459221 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b9f00ad1b7' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
