Debian Package Tracker
Register | Log in
Subscribe

libskia

Choose email to subscribe with

general
  • source: libskia (main)
  • version: 146.20260414~git.ef5f213+dfsg-5
  • maintainer: Debian Fonts Task Force (archive) (DMD)
  • uploaders: Filip Strömbäck [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • testing: 146.20260414~git.ef5f213+dfsg-4
  • unstable: 146.20260414~git.ef5f213+dfsg-5
versioned links
  • 146.20260414~git.ef5f213+dfsg-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 146.20260414~git.ef5f213+dfsg-5: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libskia-dev
  • libskia146
action needed
10 security issues in forky high

There are 10 open security issues in forky.

10 important issues:
  • CVE-2026-9892: Inappropriate implementation in Skia in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
  • CVE-2026-9893: Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
  • CVE-2026-9909: Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-9923: Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-9981: Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-9983: Type Confusion in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-9998: Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-10009: Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-10011: Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-10012: Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Created: 2026-05-29 Last update: 2026-05-29 22:33
testing migrations
  • excuses:
    • Migration status for libskia (146.20260414~git.ef5f213+dfsg-4 to 146.20260414~git.ef5f213+dfsg-5): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Autopkgtest for skia-pathops/0.9.2-2: amd64: Pass, arm64: Pass, i386: Test triggered, ppc64el: Pass, riscv64: Test triggered
    • ∙ ∙ Too young, only 0 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/libs/libskia.html
    • ∙ ∙ Reproduced on amd64 - info
    • ∙ ∙ Reproduced on arm64 - info
    • ∙ ∙ Reproduced on armhf - info
    • ∙ ∙ Reproduced on i386 - info
    • Not considered
news
[rss feed]
  • [2026-05-29] Accepted libskia 146.20260414~git.ef5f213+dfsg-5 (source) into unstable (Filip Strömbäck)
  • [2026-05-26] libskia 146.20260414~git.ef5f213+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2026-05-19] Accepted libskia 146.20260414~git.ef5f213+dfsg-4 (source) into unstable (Filip Strömbäck)
  • [2026-05-18] libskia 146.20260414~git.ef5f213+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2026-05-08] Accepted libskia 146.20260414~git.ef5f213+dfsg-3 (source) into unstable (Filip Strömbäck)
  • [2026-05-07] Accepted libskia 146.20260414~git.ef5f213+dfsg-2 (source) into unstable (Filip Strömbäck)
  • [2026-05-05] libskia 146.20260414~git.ef5f213+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-29] Accepted libskia 146.20260414~git.ef5f213+dfsg-1 (source) into unstable (Filip Strömbäck)
  • [2026-04-06] libskia 146.20260311+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2026-03-31] Accepted libskia 146.20260311+dfsg-4 (source) into unstable (Filip Strömbäck)
  • [2026-03-30] Accepted libskia 146.20260311+dfsg-3 (source) into unstable (Filip Strömbäck)
  • [2026-03-30] Accepted libskia 146.20260311+dfsg-2 (source) into unstable (Filip Strömbäck)
  • [2026-03-29] Accepted libskia 146.20260311+dfsg-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Filip Strömbäck)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 146.20260311+dfsg-4ubuntu1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing