Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to cause a Denial of Service (DoS) via sending a crafted input.
There’s a suggested patch for this in https://github.com/nothings/stb/pull/1995, but it was rejected without comment, presumably because it was drafted with AI/LLM assistance. The patch is straightforward enough and appears sensible enough to consider applying it downstream. Nothing in EPEL currently depends on the stb_sprintf library subpackage.
FEDORA-2026-ee846faf9d (stb-0^20260802.2c980bb-2.fc46) has been submitted as an update to Fedora 46. https://bodhi.fedoraproject.org/updates/FEDORA-2026-ee846faf9d
FEDORA-2026-ee846faf9d (stb-0^20260802.2c980bb-2.fc46) has been pushed to the Fedora 46 stable repository. If problem still persists, please make note of it in this bug report.