Skip to content

Potential Vulnerability in Cloned Code#21422

Merged
dpiparo merged 1 commit intoroot-project:masterfrom
bugfinderbot:codeclone-detection/root-347538ef-329-0
Feb 28, 2026
Merged

Potential Vulnerability in Cloned Code#21422
dpiparo merged 1 commit intoroot-project:masterfrom
bugfinderbot:codeclone-detection/root-347538ef-329-0

Conversation

@bugfinderbot
Copy link

This PR fixes a potential security vulnerability in png_push_read_chunk() that was cloned from pnggroup/libpng@347538e but did not receive the security patch.

Details:

Affected Function: png_push_read_chunk() in pngpread.c
Original Fix: pnggroup/libpng@347538e

What this PR does:

This PR applies the same security patch that was applied to the original repository to eliminate the potential vulnerability in the cloned code.

References:

pnggroup/libpng@347538e

Please review and merge this PR to ensure your repository is protected against this potential vulnerability.

@bugfinderbot bugfinderbot requested a review from couet as a code owner February 28, 2026 10:05
@github-actions
Copy link

Test Results

    22 files      22 suites   3d 6h 21m 58s ⏱️
 3 808 tests  3 806 ✅ 1 💤 1 ❌
76 614 runs  76 604 ✅ 9 💤 1 ❌

For more details on these failures, see this check.

Results for commit 70bda56.

@dpiparo dpiparo merged commit e082dce into root-project:master Feb 28, 2026
27 of 30 checks passed
@dpiparo
Copy link
Member

dpiparo commented Feb 28, 2026

/backport to 6.26, 6.28, 6.30, 6.32, 6.36, 6.38

@root-project-bot
Copy link

Something went wrong with the backport to 6.26: @dpiparo please see the logs

@dpiparo
Copy link
Member

dpiparo commented Feb 28, 2026

/backport to 6.36, 6.38

@root-project-bot
Copy link

This PR has been backported to

@dpiparo
Copy link
Member

dpiparo commented Feb 28, 2026

/backport to 6.32, 6.30

@root-project-bot
Copy link

Something went wrong with the backport to 6.30: @dpiparo please see the logs

@dpiparo
Copy link
Member

dpiparo commented Feb 28, 2026

/backport to 6.28

@root-project-bot
Copy link

Something went wrong with the backport to 6.28: @dpiparo please see the logs

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants