Advisories ยป MGASA-2021-0234

Updated librsvg packages fix a security vulnerability

Publication date: 08 Jun 2021
Modification date: 07 Jun 2021
Type: security
Affected Mageia releases : 7
CVE: CVE-2021-25900

Description

This update patches the vendored `smallvec` Rust crate in librsvg to fix a security vulnerability:

The Iterator implementation mishandles destructors, leading to a double free (CVE-2021-25900).
                

References

SRPMS

7/core