{"id":"USN-8559-1","summary":"rlottie vulnerabilities","details":"It was discovered that rlottie incorrectly handled certain shift\noperations. An attacker could possibly use this issue to cause rlottie\nto read out of bounds, resulting in a denial of service or exposing\nsensitive information. (CVE-2026-10305)\n\nIt was discovered that rlottie did not properly limit recursion when\nprocessing certain Lottie animations. An attacker could possibly use\nthis issue to cause rlottie to crash, resulting in a denial of service.\n(CVE-2026-47306)\n\nIt was discovered that rlottie incorrectly handled certain span\ncoordinates. An attacker could possibly use this issue to cause a\nstack-based buffer overflow, resulting in a denial of service or\npossibly the execution of arbitrary code. (CVE-2026-47318)\n\nIt was discovered that rlottie incorrectly handled certain path data.\nAn attacker could possibly use this issue to cause rlottie to allocate\nan excessive amount of memory, resulting in a denial of service.\n(CVE-2026-47319)\n\nIt was discovered that rlottie did not properly limit recursion and\ncould access an uninitialized pointer when processing certain Lottie\nanimations. An attacker could possibly use this issue to cause rlottie\nto crash, resulting in a denial of service. (CVE-2026-47320)\n\nIt was discovered that rlottie incorrectly handled certain array\nlengths in the bundled FreeType raster code. An attacker could possibly\nuse this issue to cause an out-of-bounds write, resulting in a denial\nof service or possibly the execution of arbitrary code. This issue only\naffected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-8916)","modified":"2026-07-21T13:20:12.191523005Z","published":"2026-07-20T12:19:36Z","related":["UBUNTU-CVE-2026-10305","UBUNTU-CVE-2026-47306","UBUNTU-CVE-2026-47318","UBUNTU-CVE-2026-47319","UBUNTU-CVE-2026-47320","UBUNTU-CVE-2026-8916"],"upstream":["CVE-2026-10305","CVE-2026-47306","CVE-2026-47318","CVE-2026-47319","CVE-2026-47320","CVE-2026-8916","UBUNTU-CVE-2026-10305","UBUNTU-CVE-2026-47306","UBUNTU-CVE-2026-47318","UBUNTU-CVE-2026-47319","UBUNTU-CVE-2026-47320","UBUNTU-CVE-2026-8916"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8559-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-8916"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-10305"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-47306"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-47318"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-47319"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-47320"}],"affected":[{"package":{"name":"rlottie","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/rlottie?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0~git20200305.a717479+dfsg-1ubuntu0.1~esm3"}]}],"versions":["0~git20190721.24346d0+dfsg-2","0~git20190721.24346d0+dfsg-2build1","0~git20200305.a717479+dfsg-1","0~git20200305.a717479+dfsg-1ubuntu0.1~esm1","0~git20200305.a717479+dfsg-1ubuntu0.1~esm2"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"librlottie0-1","binary_version":"0~git20200305.a717479+dfsg-1ubuntu0.1~esm3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8559-1.json","cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-8916"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-10305"},{"id":"CVE-2026-47306","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-47318","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-47319","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-47320","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:Pro:20.04:LTS"}}},{"package":{"name":"rlottie","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/rlottie?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1+dfsg-2ubuntu0.2+esm1"}]}],"versions":["0.1+dfsg-2","0.1+dfsg-2ubuntu0.1","0.1+dfsg-2ubuntu0.2"],"ecosystem_specific":{"binaries":[{"binary_name":"librlottie0-1","binary_version":"0.1+dfsg-2ubuntu0.2+esm1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8559-1.json","cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-8916"},{"id":"CVE-2026-10305","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-47306","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-47318","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-47319","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-47320","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}]}],"ecosystem":"Ubuntu:Pro:22.04:LTS"}}},{"package":{"name":"rlottie","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/rlottie?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1+dfsg-4ubuntu1.1+esm1"}]}],"versions":["0.1+dfsg-4ubuntu1","0.1+dfsg-4ubuntu1.1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"librlottie0-1","binary_version":"0.1+dfsg-4ubuntu1.1+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8559-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:24.04:LTS","cves":[{"id":"CVE-2026-8916","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-10305"},{"id":"CVE-2026-47306","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-47318","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-47319","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-47320"}]}}},{"package":{"name":"rlottie","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/rlottie?arch=source&distro=esm-apps%2Fresolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.1+dfsg-4.3ubuntu0.1~esm1"}]}],"versions":["0.1+dfsg-4.2","0.1+dfsg-4.3"],"ecosystem_specific":{"binaries":[{"binary_version":"0.1+dfsg-4.3ubuntu0.1~esm1","binary_name":"librlottie0-1"}],"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro"},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2026-8916","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2026-10305","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2026-47306","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2026-47318"},{"id":"CVE-2026-47319","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},{"score":"medium","type":"Ubuntu"}]},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H","type":"CVSS_V3"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2026-47320"}],"ecosystem":"Ubuntu:Pro:26.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8559-1.json"}}],"schema_version":"1.7.5"}