Bug 2540386 (CVE-2026-88367) - CVE-2026-88367 nanosvg: nanosvg: Denial of Service via crafted SVG document with large stroke width
Summary: CVE-2026-88367 nanosvg: nanosvg: Denial of Service via crafted SVG document w...
Keywords:
Status: NEW
Alias: CVE-2026-88367
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2540655 2540656 2540657 2540658 2540660 2540661 2540659
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-24 16:37 UTC by OSIDB Bzimport
Modified: 2026-09-24 18:19 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-24 16:37:11 UTC
NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasterization. A specially crafted SVG document containing an extremely large stroke-width can cause floating-point rounding to produce a zero subdivision angle. The subsequent arc division yields infinity, which is converted to int without range validation, resulting in undefined behavior and process termination, leading to denial of service.


Note You need to log in before you can comment on or make changes to this bug.