Skip to content

Potential Vulnerability in Cloned Code#21504

Merged
dpiparo merged 1 commit intoroot-project:masterfrom
tabudz:CVE-2017-15232
Mar 6, 2026
Merged

Potential Vulnerability in Cloned Code#21504
dpiparo merged 1 commit intoroot-project:masterfrom
tabudz:CVE-2017-15232

Conversation

@tabudz
Copy link

@tabudz tabudz commented Mar 5, 2026

Summary

Our tool detected a potential vulnerability in graf2d/asimage/src/libAfterImage/libjpeg/jdpostct.c which was cloned from libjpeg-turbo/libjpeg-turbo but did not receive the security patch applied. The original issue was reported and fixed under https://nvd.nist.gov/vuln/detail/cve-2017-15232.

Proposed Fix

Apply the same patch as the one in libjpeg-turbo/libjpeg-turbo to eliminate the vulnerability.

Reference

https://nvd.nist.gov/vuln/detail/cve-2017-15232
libjpeg-turbo/libjpeg-turbo@1ecd9a5

@tabudz tabudz requested a review from couet as a code owner March 5, 2026 14:32
@dpiparo
Copy link
Member

dpiparo commented Mar 5, 2026

Hi @tabudz .Thanks for this PR.
Might I ask if you are behind this PR, too #21418? It was submitted twice, but apparently by a tool and not a human.

@tabudz
Copy link
Author

tabudz commented Mar 5, 2026

Hi @dpiparo, sorry for the duplicated PRs. That was a mistake on our side. Thanks for the heads-up. Closed the PR.

@tabudz tabudz closed this Mar 5, 2026
@dpiparo dpiparo reopened this Mar 6, 2026
@dpiparo
Copy link
Member

dpiparo commented Mar 6, 2026

It's me who thanks you. I appreciate your approach. this PR is good, I reopened it. One of the ones I was referring to is, for example, #21420, that looks like a hiccup in a script automating some procedure.

@dpiparo dpiparo merged commit 922c23a into root-project:master Mar 6, 2026
23 of 30 checks passed
@dpiparo
Copy link
Member

dpiparo commented Mar 6, 2026

/backport to 6.38, 6.36, 6.32, 6.30, 6.28, 6.26

@root-project-bot
Copy link

Something went wrong with the backport to 6.38: @dpiparo please see the logs

@tabudz
Copy link
Author

tabudz commented Mar 6, 2026

Thank you for the kind words, @dpiparo. Since some of our previous PRs had already been merged, I assumed this one was a duplicate and closed it right away. You are correct that there was a defect in the automation script, and we will fix it soon. Since the PR has now been merged, may I ask whether you have any concerns about us submitting this as a CVE?

@dpiparo
Copy link
Member

dpiparo commented Mar 6, 2026

Could we please perhaps discuss over email the matter? The address is on our security policy https://github.com/root-project/root?tab=security-ov-file

@dpiparo
Copy link
Member

dpiparo commented Mar 6, 2026

/backport to 6.36, 6.32, 6.30, 6.28, 6.26

@root-project-bot
Copy link

Something went wrong with the backport to 6.36: @dpiparo please see the logs

@dpiparo dpiparo unassigned couet and dpiparo Mar 6, 2026
@dpiparo
Copy link
Member

dpiparo commented Mar 6, 2026

/backport to 6.32, 6.30, 6.28, 6.26

@root-project-bot
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants