CVE-2026-10305

NameCVE-2026-10305
DescriptionOut-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: before 223a2a41ba4f462e4abe767bebba49a366c9b9fd.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rlottie (PTS)bullseye0.1+dfsg-2vulnerable
bullseye (security)0.1+dfsg-2+deb11u1vulnerable
bookworm0.1+dfsg-4+deb12u1vulnerable
trixie0.1+dfsg-4.2+deb13u1vulnerable
forky, sid0.1+dfsg-4.3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rlottiesource(unstable)(unfixed)

Notes

https://github.com/Samsung/rlottie/pull/587
https://github.com/Samsung/rlottie/commit/b4f5101a4d1a8da60cc14cfd05608551b3448c77

Search for package or bug name: Reporting problems