poky/meta/recipes-gnome
Archana Polampalli c172c46096 gdk-pixbuf: fix CVE-2025-7345
A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function
(io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing
maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding,
allowing out-of-bounds reads from heap memory, potentially causing application crashes or
arbitrary code execution.

(From OE-Core rev: 78a52a7feb995b4ab4f4df6b16feaac60f6ad59b)

Signed-off-by: Archana Polampalli <archana.polampalli@windriver.com>
Signed-off-by: Steve Sakoman <steve@sakoman.com>
2025-07-21 09:07:21 -07:00
..
epiphany epiphany: update 45.3 -> 46.0 2024-04-04 14:05:03 +01:00
gcr gcr: Fix LICENSE 2024-09-19 05:11:35 -07:00
gdk-pixbuf gdk-pixbuf: fix CVE-2025-7345 2025-07-21 09:07:21 -07:00
gi-docgen gi-docgen: upgrade 2023.1 -> 2023.3 2023-12-02 17:18:57 +00:00
gnome gnomebase.bbclass: Use meson as default buildsystem 2023-11-13 11:38:03 +00:00
gobject-introspection gobject-introspection: depend on setuptools to obtain distutils module 2023-12-21 10:38:29 +00:00
gsettings-desktop-schemas gsettings-desktop-schemas: update 45.0 -> 46.0 2024-03-22 16:25:08 +00:00
gtk-doc gtk-doc: don't use docdir set in environment in gtkdocize 2024-01-12 11:54:05 +00:00
gtk+ gtk+: add missing libdrm dependency 2025-06-13 08:58:01 -07:00
hicolor-icon-theme meta/meta-selftest/meta-skeleton: Update LICENSE variable to use SPDX license identifiers 2022-02-20 16:45:25 +00:00
json-glib json-glib: upgrade 1.6.6 -> 1.8.0 2023-12-06 22:55:49 +00:00
libadwaita libadwaita: upgrade 1.5.1 -> 1.5.2 2024-09-09 06:08:10 -07:00
libdazzle gnomebase.bbclass: Use meson as default buildsystem 2023-11-13 11:38:03 +00:00
libgudev libgudev: Pass export-dynamic to linker directly. 2024-01-21 12:27:12 +00:00
libhandy libhandy: upgrade 1.8.2 -> 1.8.3 2024-03-01 09:28:51 +00:00
libnotify libnotify: upgrade 0.8.2 -> 0.8.3 2023-11-23 12:46:41 +00:00
libportal libportal: fix rare build race 2024-07-17 05:36:13 -07:00
librsvg librsvg: don't try to run target code at build time 2024-08-26 05:18:44 -07:00
libsecret libsecret: upgrade 0.21.2 -> 0.21.4 2024-03-01 09:28:51 +00:00
libxmlb libxmlb: upgrade 0.3.14 -> 0.3.15 2024-01-19 12:21:23 +00:00