Debian Package Tracker
Register | Log in
Subscribe

librsvg

Choose email to subscribe with

general
  • source: librsvg (main)
  • version: 2.63.2+dfsg-1
  • maintainer: Debian GNOME Maintainers (archive) (DMD)
  • uploaders: Laurent Bigonville [DMD] – Emilio Pozuelo Monfort [DMD] – Jeremy Bícha [DMD]
  • arch: all any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.50.3+dfsg-1+deb11u1
  • o-o-sec: 2.50.3+dfsg-1+deb11u1
  • oldstable: 2.54.7+dfsg-1~deb12u1
  • old-sec: 2.54.7+dfsg-1~deb12u1
  • stable: 2.60.0+dfsg-1
  • testing: 2.63.2+dfsg-1
  • unstable: 2.63.2+dfsg-1
versioned links
  • 2.50.3+dfsg-1+deb11u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.54.7+dfsg-1~deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.60.0+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.63.2+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • gir1.2-rsvg-2.0
  • librsvg2-2 (11 bugs: 0, 11, 0, 0)
  • librsvg2-bin (15 bugs: 0, 12, 3, 0)
  • librsvg2-common (5 bugs: 0, 5, 0, 0)
  • librsvg2-dev
  • librsvg2-doc
  • librsvg2-tests
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-96889: A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Created: 2026-09-24 Last update: 2026-10-09 18:30
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-96889: A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.
Created: 2026-09-24 Last update: 2026-10-09 18:30
Multiarch hinter reports 1 issue(s) normal
There are issues with the multiarch metadata for this package.
  • librsvg2-tests could be marked Multi-Arch: same
Created: 2026-10-06 Last update: 2026-10-11 19:32
Does not build reproducibly during testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2026-04-15 Last update: 2026-10-11 19:32
2 new commits since last upload, is it time to release? normal
vcswatch reports that this package seems to have new commits in its VCS but has not yet updated debian/changelog. You should consider updating the Debian changelog and uploading this new version into the archive.

Here are the relevant commit logs:
commit 963d687dac4ab702cffe2a36c1bd61a3f71fc82f
Author: Jeremy Bícha <jbicha@ubuntu.com>
Date:   Fri Oct 9 13:32:07 2026 +0200

    Set XS-Vendored-Sources-Rust
    
    as required for inclusion in Ubuntu main
    
    https://ubuntu.com/project/docs/MIR/mir-rust/#rust-vendored-sources-tracking
    
    This is updated automatically by debian/rules vendor
    but I forgot to include the field in debian/control earlier

commit 909e0219a5d1ad18ad982730d28cbf7690b6676a
Author: Jeremy Bícha <jbicha@ubuntu.com>
Date:   Sat Oct 3 17:22:18 2026 +0200

    Opt into Salsa CI
Created: 2026-10-04 Last update: 2026-10-09 13:33
news
[rss feed]
  • [2026-10-10] librsvg 2.63.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-10-03] Accepted librsvg 2.63.2+dfsg-1 (source) into unstable (Jeremy Bícha)
  • [2026-04-14] librsvg 2.62.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-08] Accepted librsvg 2.62.1+dfsg-1 (source) into unstable (Jeremy Bícha)
  • [2025-12-18] librsvg 2.61.3+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2025-12-10] Accepted librsvg 2.61.3+dfsg-3 (source) into unstable (Jeremy Bícha)
  • [2025-11-11] librsvg 2.61.3+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-11-04] Accepted librsvg 2.61.3+dfsg-2 (source) into unstable (Jeremy Bícha)
  • [2025-11-04] Accepted librsvg 2.61.3+dfsg-1 (source) into experimental (Jeremy Bícha)
  • [2025-10-28] Accepted librsvg 2.61.2+dfsg-1 (source) into experimental (Jeremy Bícha)
  • [2025-03-24] librsvg 2.60.0+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-19] Accepted librsvg 2.60.0+dfsg-1 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-02-17] librsvg 2.59.90+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2025-02-12] Accepted librsvg 2.59.90+dfsg-2 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2025-02-11] Accepted librsvg 2.59.90+dfsg-1 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-11-26] Accepted librsvg 2.59.2+dfsg-1 (source) into unstable (Nathan Pratta Teodosio) (signed by: Sebastien Bacher)
  • [2024-10-06] librsvg 2.59.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-30] Accepted librsvg 2.59.1+dfsg-1 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-09-20] librsvg 2.59.0+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2024-09-14] Accepted librsvg 2.59.0+dfsg-3 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-09-14] Accepted librsvg 2.59.0+dfsg-2 (source) into unstable (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-09-13] Accepted librsvg 2.59.0+dfsg-1 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-09-11] Accepted librsvg 2.58.94+dfsg-3 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-09-10] Accepted librsvg 2.58.94+dfsg-2 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-09-04] Accepted librsvg 2.58.94+dfsg-1 (source) into experimental (Alessandro Astone) (signed by: Jeremy Bicha)
  • [2024-08-27] Accepted librsvg 2.58.93+dfsg-5 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-08-21] Accepted librsvg 2.58.93+dfsg-4 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-08-15] Accepted librsvg 2.58.93+dfsg-3 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-08-15] Accepted librsvg 2.58.93+dfsg-2 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • [2024-08-15] Accepted librsvg 2.58.93+dfsg-1 (source) into experimental (Jeremy Bícha) (signed by: Jeremy Bicha)
  • 1
  • 2
bugs [bug history graph]
  • all: 38 39
  • RC: 1
  • I&N: 33 34
  • M&W: 4
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.62.1+dfsg-1ubuntu1
  • 33 bugs (1 patch)

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing