Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package libXpm for openSUSE:Factory checked 
in at 2026-09-28 10:34:58
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/libXpm (Old)
 and      /work/SRC/openSUSE:Factory/.libXpm.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "libXpm"

Mon Sep 28 10:34:58 2026 rev:20 rq:1380040 version:3.5.18

Changes:
--------
--- /work/SRC/openSUSE:Factory/libXpm/libXpm.changes    2026-04-23 
17:09:22.980528416 +0200
+++ /work/SRC/openSUSE:Factory/.libXpm.new.383539/libXpm.changes        
2026-09-28 10:35:01.666238564 +0200
@@ -1,0 +2,7 @@
+Wed Sep 23 20:46:07 UTC 2026 - Stefan Dirsch <[email protected]>
+
+- 
0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch
+  * Denial of service via unsigned underflow in libXpm's write path
+    (boo#1281669, CVE-2026-94287)
+
+-------------------------------------------------------------------

New:
----
  
0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch

----------(New B)----------
  New:
- 
0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch
  * Denial of service via unsigned underflow in libXpm's write path
----------(New E)----------

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ libXpm.spec ++++++
--- /var/tmp/diff_new_pack.hrR2kN/_old  2026-09-28 10:35:02.179260058 +0200
+++ /var/tmp/diff_new_pack.hrR2kN/_new  2026-09-28 10:35:02.181260141 +0200
@@ -31,6 +31,7 @@
 Source2:        libXpm.keyring
 Source9:        baselibs.conf
 Patch0:         0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch
+Patch1:         
0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch
 BuildRequires:  /usr/bin/gzip
 BuildRequires:  autoconf
 BuildRequires:  automake

++++++ 
0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch
 ++++++
>From 3a68f818b1628d7ad96245b0f4d15a32a015b0ab Mon Sep 17 00:00:00 2001
From: Olivier Fourdan <[email protected]>
Date: Fri, 11 Sep 2026 16:21:16 +0200
Subject: [PATCH] ParsePixels: reject zero-dimension XPM images

The existing dimension checks in ParsePixels() reject mismatched
zeros (width==0 with height!=0, or vice versa) but accept the case
where both width and height are zero.

As a result, a 0x0 XPM can therefore pass parsing and reach the function
WritePixels(), which computes the row loop bound as "h = height - 1"
using unsigned arithmetic.

With a zero height this underflows to UINT_MAX, causing a near-infinite
write loop.

To avoid that issue, simply reject any image with a zero width or height
dimension as an invalid XPM file.

Found by AISLE in partnership with Red Hat

AISLE-Report-PSIRTSUPT-14424

CVE-2026-94287

Reported-by: Aisle Research
Assisted-by: AI
Signed-off-by: Olivier Fourdan <[email protected]>
---
 src/parse.c | 5 +----
 1 file changed, 1 insertion(+), 4 deletions(-)

diff --git a/src/parse.c b/src/parse.c
index 268954d..2e9bfcd 100644
--- a/src/parse.c
+++ b/src/parse.c
@@ -414,10 +414,7 @@ ParsePixels(
     unsigned int a, x, y;
     int ErrorStatus;
 
-    if ((width == 0) && (height != 0))
-       return (XpmFileInvalid);
-
-    if ((height == 0) && (width != 0))
+    if (width == 0 || height == 0)
        return (XpmFileInvalid);
 
     if ((height > 0 && width >= UINT_MAX / height) ||
-- 
2.51.0

Reply via email to