{"id":"ECHO-c07a-bc81-6c75","summary":"Floating-point exception in pixman's combine_inner function triggered only\nvia the stress-test developer test binary, not the runtime library.\nThe vulnerable code is in stress-test.c which is never compiled, shipped,\nor installed in the libpixman-1-0 package present in Echo containers.\nDebian marks this as \"unimportant\" with note \"Crash in test tool, no security impact.\"\nNo upstream fix after 2.5+ years.\n\nhttps://security-tracker.debian.org/tracker/CVE-2023-37769\n","modified":"2026-09-15T03:33:36.858747220Z","published":"2025-09-15T01:09:08.738530Z","withdrawn":"2026-02-11T13:00:04.062Z","upstream":["CVE-2023-37769"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2023-37769"}],"affected":[{"package":{"name":"pixman","ecosystem":"Echo","purl":"pkg:deb/echo/pixman"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.44.0-3"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-c07a-bc81-6c75.json"}}],"schema_version":"1.9.0"}