Back Linuxsecurity Ubuntu 26.04 LTS rlottie Critical Denial of Service USN-8559
rlottie could be made to crash if it received specially crafted input. Software Description: - rlottie: library for rendering vector based animations and art Details: It was discovered that rlottie incorrectly handled certain shift operations. An attacker could possibly use this issue to cause rlottie to read out of bounds, resulting in a denial of service or exposing sensitive information. (CVE-2026-10305) It was discovered that rlottie did not properly limit recursion when processing certain Lottie animations. An attacker could possibly use this issue to cause rlottie to crash, resulting in a denial of service. (CVE-2026-47306) It was discovered that rlottie incorrectly handled certain span coordinates. An attacker could possibly use this issue to cause a stack-based buffer overflow, resulting in a denial of service or possibly the execution of arbitrary code. (CVE-2026-47318) It was discovered that rlottie incorrectly handled certain path data. An attacker could possibly u... Read the Full Advisory
rlottie could be made to crash if it received specially crafted input.
Software Description:
- rlottie: library for rendering vector based animations and art
It was discovered that rlottie incorrectly handled certain shift
operations. An attacker could possibly use this issue to cause rlottie
to read out of bounds, resulting in a denial of service or exposing
sensitive information. (CVE-2026-10305)
It was discovered that rlottie did not properly limit recursion when
processing certain Lottie animations. An attacker could possibly use
this issue to cause rlottie to crash, resulting in a denial of service.
It was discovered that rlottie incorrectly handled certain span
coordinates. An attacker could possibly use this issue to cause a
stack-based buffer overflow, resulting in a denial of service or
possibly the execution of arbitrary code. (CVE-2026-47318)
It was discovered that rlottie incorrectly handled certain path data.
An attacker could possibly u...
The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS librlottie0-1 0.1+dfsg-4.3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS librlottie0-1 0.1+dfsg-4ubuntu1.1+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS librlottie0-1 0.1+dfsg-2ubuntu0.2+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS librlottie0-1 0~git20200305.a717479+dfsg-1ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.
CVE-2026-10305, CVE-2026-47306, CVE-2026-47318, CVE-2026-47319,
Ubuntu Security Notice USN-8559-1
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
