Bug 2454217
| Summary: | CVE-2026-5313 stb: Nothings stb: Denial of Service in GIF Decoder via stbi__gif_load_next function [epel-all] | ||
|---|---|---|---|
| Product: | [Fedora] Fedora EPEL | Reporter: | Sandipan Roy <saroy> |
| Component: | stb | Assignee: | Ben Beasley <code> |
| Status: | ASSIGNED --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | epel10 | CC: | code, mhroncok |
| Target Milestone: | --- | Keywords: | Security, SecurityTracking |
| Target Release: | --- | ||
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | {"flaws": ["6543152d-d68d-4670-a247-c4329cc39a2e"]} | ||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 2454134 | ||
|
Description
Sandipan Roy
2026-04-02 06:03:38 UTC
https://www.cve.org/CVERecord?id=CVE-2026-5313 Since this has not been triaged or fixed upstream, and no suggested patch was published, there’s nothing to be done at this time. I’m not planning to try to evaluate the validity of the CVE and devise a downstream patch myself. If a suggested patch appears, I’m happy to evaluate it ahead of upstream if necessary. |