Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libXpm for openSUSE:Factory checked in at 2026-09-28 10:34:58 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libXpm (Old) and /work/SRC/openSUSE:Factory/.libXpm.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libXpm" Mon Sep 28 10:34:58 2026 rev:20 rq:1380040 version:3.5.18 Changes: -------- --- /work/SRC/openSUSE:Factory/libXpm/libXpm.changes 2026-04-23 17:09:22.980528416 +0200 +++ /work/SRC/openSUSE:Factory/.libXpm.new.383539/libXpm.changes 2026-09-28 10:35:01.666238564 +0200 @@ -1,0 +2,7 @@ +Wed Sep 23 20:46:07 UTC 2026 - Stefan Dirsch <[email protected]> + +- 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch + * Denial of service via unsigned underflow in libXpm's write path + (boo#1281669, CVE-2026-94287) + +------------------------------------------------------------------- New: ---- 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch ----------(New B)---------- New: - 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch * Denial of service via unsigned underflow in libXpm's write path ----------(New E)---------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libXpm.spec ++++++ --- /var/tmp/diff_new_pack.hrR2kN/_old 2026-09-28 10:35:02.179260058 +0200 +++ /var/tmp/diff_new_pack.hrR2kN/_new 2026-09-28 10:35:02.181260141 +0200 @@ -31,6 +31,7 @@ Source2: libXpm.keyring Source9: baselibs.conf Patch0: 0001-Fix-CVE-2026-4367-Out-of-bounds-read-in-xpmNextWord.patch +Patch1: 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch BuildRequires: /usr/bin/gzip BuildRequires: autoconf BuildRequires: automake ++++++ 0001-boo1281669_CVE-2026-94287_ParsePixels-reject-zero-dimension-XPM-images.patch ++++++ >From 3a68f818b1628d7ad96245b0f4d15a32a015b0ab Mon Sep 17 00:00:00 2001 From: Olivier Fourdan <[email protected]> Date: Fri, 11 Sep 2026 16:21:16 +0200 Subject: [PATCH] ParsePixels: reject zero-dimension XPM images The existing dimension checks in ParsePixels() reject mismatched zeros (width==0 with height!=0, or vice versa) but accept the case where both width and height are zero. As a result, a 0x0 XPM can therefore pass parsing and reach the function WritePixels(), which computes the row loop bound as "h = height - 1" using unsigned arithmetic. With a zero height this underflows to UINT_MAX, causing a near-infinite write loop. To avoid that issue, simply reject any image with a zero width or height dimension as an invalid XPM file. Found by AISLE in partnership with Red Hat AISLE-Report-PSIRTSUPT-14424 CVE-2026-94287 Reported-by: Aisle Research Assisted-by: AI Signed-off-by: Olivier Fourdan <[email protected]> --- src/parse.c | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/src/parse.c b/src/parse.c index 268954d..2e9bfcd 100644 --- a/src/parse.c +++ b/src/parse.c @@ -414,10 +414,7 @@ ParsePixels( unsigned int a, x, y; int ErrorStatus; - if ((width == 0) && (height != 0)) - return (XpmFileInvalid); - - if ((height == 0) && (width != 0)) + if (width == 0 || height == 0) return (XpmFileInvalid); if ((height > 0 && width >= UINT_MAX / height) || -- 2.51.0
