Bug 2341675

Summary: CVE-2024-57719 CVE-2024-57720 CVE-2024-57721 CVE-2024-57722 CVE-2024-57723 CVE-2024-57724 lunasvg: various flaws [epel-9]
Product: [Fedora] Fedora EPEL Reporter: Michal Findra <mfindra>
Component: lunasvgAssignee: Davide Cavalca <davide>
Status: CLOSED ERRATA QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: epel9CC: davide, jonathan
Target Milestone: ---Keywords: Reopened, Security, SecurityTracking
Target Release: ---   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard: {"flaws": ["313930a5-f7e3-41d2-a191-8caa5ff5894c", "52aefd47-8c44-4d09-983e-9dca249dfc54", "64883802-0bad-475f-87bc-c57bb555265e", "f60d5092-21b1-4b0c-a950-98fa799324de", "dce03344-5133-4488-b67a-6fc39931e6bf", "98432a12-e743-41a1-9894-65d7255277d5"]}
Fixed In Version: lunasvg-3.5.0-1.fc44 lunasvg-3.5.0-1.el10_2 lunasvg-3.5.0-1.el9 lunasvg-3.5.0-1.fc42 lunasvg-3.5.0-1.fc43 Doc Type: No Doc Update
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2025-12-01 10:01:17 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 2341644, 2341645, 2341646, 2341647, 2341648, 2341649    

Description Michal Findra 2025-01-23 08:01:53 UTC
More information about these security flaws is available in the following bugs:

https://bugzilla.redhat.com/show_bug.cgi?id=2341647
https://bugzilla.redhat.com/show_bug.cgi?id=2341649
https://bugzilla.redhat.com/show_bug.cgi?id=2341645
https://bugzilla.redhat.com/show_bug.cgi?id=2341646
https://bugzilla.redhat.com/show_bug.cgi?id=2341648
https://bugzilla.redhat.com/show_bug.cgi?id=2341644

Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

Comment 3 Fedora Update System 2025-12-01 09:57:00 UTC
FEDORA-2025-49d2ea998c (imhex-1.37.4-3.fc44 and lunasvg-3.5.0-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-49d2ea998c

Comment 4 Fedora Update System 2025-12-01 10:01:17 UTC
FEDORA-2025-49d2ea998c (imhex-1.37.4-3.fc44 and lunasvg-3.5.0-1.fc44) has been pushed to the Fedora 44 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 5 Fedora Update System 2025-12-01 10:08:09 UTC
FEDORA-2025-58c0baba42 (imhex-1.37.4-3.fc43 and lunasvg-3.5.0-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-58c0baba42

Comment 6 Fedora Update System 2025-12-01 10:29:06 UTC
FEDORA-2025-9b6b49071f (imhex-1.37.4-3.fc42 and lunasvg-3.5.0-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-9b6b49071f

Comment 7 Fedora Update System 2025-12-01 10:47:00 UTC
FEDORA-EPEL-2025-85c58e7712 (imhex-1.37.4-3.el10_2 and lunasvg-3.5.0-1.el10_2) has been submitted as an update to Fedora EPEL 10.2.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-85c58e7712

Comment 8 Fedora Update System 2025-12-01 11:08:28 UTC
FEDORA-EPEL-2025-00dab21def (imhex-1.37.4-3.el10_1 and lunasvg-3.5.0-1.el10_1) has been submitted as an update to Fedora EPEL 10.1.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-00dab21def

Comment 9 Fedora Update System 2025-12-01 12:20:11 UTC
FEDORA-EPEL-2025-51d4080725 (imhex-1.37.4-3.el9 and lunasvg-3.5.0-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-51d4080725

Comment 10 Fedora Update System 2025-12-02 00:57:06 UTC
FEDORA-EPEL-2025-00dab21def has been pushed to the Fedora EPEL 10.1 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-00dab21def

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 11 Fedora Update System 2025-12-02 01:28:05 UTC
FEDORA-EPEL-2025-85c58e7712 has been pushed to the Fedora EPEL 10.2 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-85c58e7712

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 12 Fedora Update System 2025-12-02 01:35:01 UTC
FEDORA-EPEL-2025-51d4080725 has been pushed to the Fedora EPEL 9 testing repository.

You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2025-51d4080725

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 13 Fedora Update System 2025-12-02 01:50:50 UTC
FEDORA-2025-9b6b49071f has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-9b6b49071f`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-9b6b49071f

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 14 Fedora Update System 2025-12-02 02:10:24 UTC
FEDORA-2025-58c0baba42 has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-58c0baba42`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-58c0baba42

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 15 Fedora Update System 2025-12-10 00:25:41 UTC
FEDORA-EPEL-2025-00dab21def (imhex-1.37.4-3.el10_1 and lunasvg-3.5.0-1.el10_1) has been pushed to the Fedora EPEL 10.1 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 16 Fedora Update System 2025-12-10 00:25:42 UTC
FEDORA-EPEL-2025-85c58e7712 (imhex-1.37.4-3.el10_2 and lunasvg-3.5.0-1.el10_2) has been pushed to the Fedora EPEL 10.2 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 17 Fedora Update System 2025-12-10 00:38:51 UTC
FEDORA-EPEL-2025-51d4080725 (imhex-1.37.4-3.el9 and lunasvg-3.5.0-1.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 18 Fedora Update System 2025-12-10 00:48:01 UTC
FEDORA-2025-9b6b49071f (imhex-1.37.4-3.fc42 and lunasvg-3.5.0-1.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 19 Fedora Update System 2025-12-10 01:33:13 UTC
FEDORA-2025-58c0baba42 (imhex-1.37.4-3.fc43 and lunasvg-3.5.0-1.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.