Skip to content
Ubuntu 26.04 LTS rlottie Critical Denial of Service USN-8559

Ubuntu 26.04 LTS rlottie Critical Denial of Service USN-8559

Linuxsecurity LinuxSecurity Advisories July 20, 2026

rlottie could be made to crash if it received specially crafted input. Software Description: - rlottie: library for rendering vector based animations and art Details: It was discovered that rlottie incorrectly handled certain shift operations. An attacker could possibly use this issue to cause rlottie to read out of bounds, resulting in a denial of service or exposing sensitive information. (CVE-2026-10305) It was discovered that rlottie did not properly limit recursion when processing certain Lottie animations. An attacker could possibly use this issue to cause rlottie to crash, resulting in a denial of service. (CVE-2026-47306) It was discovered that rlottie incorrectly handled certain span coordinates. An attacker could possibly use this issue to cause a stack-based buffer overflow, resulting in a denial of service or possibly the execution of arbitrary code. (CVE-2026-47318) It was discovered that rlottie incorrectly handled certain path data. An attacker could possibly u... Read the Full Advisory

rlottie could be made to crash if it received specially crafted input.

Software Description:

- rlottie: library for rendering vector based animations and art

It was discovered that rlottie incorrectly handled certain shift

operations. An attacker could possibly use this issue to cause rlottie

to read out of bounds, resulting in a denial of service or exposing

sensitive information. (CVE-2026-10305)

It was discovered that rlottie did not properly limit recursion when

processing certain Lottie animations. An attacker could possibly use

this issue to cause rlottie to crash, resulting in a denial of service.

It was discovered that rlottie incorrectly handled certain span

coordinates. An attacker could possibly use this issue to cause a

stack-based buffer overflow, resulting in a denial of service or

possibly the execution of arbitrary code. (CVE-2026-47318)

It was discovered that rlottie incorrectly handled certain path data.

An attacker could possibly u...

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS librlottie0-1 0.1+dfsg-4.3ubuntu0.1~esm1 Available with Ubuntu Pro Ubuntu 24.04 LTS librlottie0-1 0.1+dfsg-4ubuntu1.1+esm1 Available with Ubuntu Pro Ubuntu 22.04 LTS librlottie0-1 0.1+dfsg-2ubuntu0.2+esm1 Available with Ubuntu Pro Ubuntu 20.04 LTS librlottie0-1 0~git20200305.a717479+dfsg-1ubuntu0.1~esm3 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

CVE-2026-10305, CVE-2026-47306, CVE-2026-47318, CVE-2026-47319,

CVE-2026-47320, CVE-2026-8916

Ubuntu Security Notice USN-8559-1

Get the latest Linux and open source security news straight to your inbox.