Debian Security Advisory

DLA-3179-1 pixman -- LTS security update

Date Reported:
07 Nov 2022
Affected Packages:
pixman
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2022-44638.
More information:

It was discovered that there was a potential out-of-bounds write vulnerability in pixman, a pixel-manipulation library used in many Linux graphical applications.

  • CVE-2022-44638

    In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.

For Debian 10 Buster, this problem has been fixed in version 0.36.0-1+deb10u1.

We recommend that you upgrade your pixman packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS