[CLSA-2026:1778796429] cairo: Fix of CVE-2020-35492
Type:
security
Severity:
Important
Release date:
2026-05-14 22:07:19 UTC
Description:
- CVE-2020-35492: stack buffer overflow in _inplace_src_spans() in src/cairo-image-compositor.c via a crafted input file causing out-of-bounds write through the r->_buf stack mask pointer
Updated packages:
  • cairo-1.15.12-4.amzn2.0.1.tuxcare.els1.i686.rpm
    sha:c3e6d5d051ba72e07cf60c8d404ef49d4828b8be2ff78138d6b6c43cb85e2907
  • cairo-1.15.12-4.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:9a8b08b5369d63b880cab72e191dca91b0cc956bc7a41d6034c76cc9b31cadfe
  • cairo-devel-1.15.12-4.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:74d6720b9247ea8e911cc62ec04e58794742cb87b84369500d53f7ccb2f188c8
  • cairo-gobject-1.15.12-4.amzn2.0.1.tuxcare.els1.i686.rpm
    sha:9d81e13a6e1ed32374fbe8d638b1da35fc50a76f2d4104d09e7415f112235e57
  • cairo-gobject-1.15.12-4.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:6f4f5d47022d69a15eef2223a1880a0259f07cb624cde1e889cbedf028755d92
  • cairo-gobject-devel-1.15.12-4.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:9cdad0f2305047a643603856ad52d632658cf794a5d7dd7d52c0d185563df1cd
  • cairo-tools-1.15.12-4.amzn2.0.1.tuxcare.els1.x86_64.rpm
    sha:cbd4429d32758167d7e8cbb52062c6ad7129b913163086da7f45a0bc87b47787
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.