MGASA-2026-0214

Source
https://advisories.mageia.org/MGASA-2026-0214.html
Import Source
https://advisories.mageia.org/MGASA-2026-0214.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0214
Upstream
Published
2026-06-16T04:58:51Z
Modified
2026-06-16T05:00:04.975013304Z
Summary
Updated lcms2 packages fix security vulnerability
Details

Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplication. (CVE-2026-41254)

References
Credits

Affected packages

Mageia:9 / lcms2

Package

Name
lcms2
Purl
pkg:rpm/mageia/lcms2?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.15-2.1.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0214.json"