Debian Package Tracker
Register | Log in
Subscribe

libskia

Choose email to subscribe with

general
  • source: libskia (main)
  • version: 146.20260602~git.3476902+dfsg-4
  • maintainer: Debian Fonts Task Force (archive) (DMD)
  • uploaders: Filip Strömbäck [DMD]
  • arch: any
  • std-ver: 4.7.4
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • testing: 146.20260602~git.3476902+dfsg-2
  • unstable: 146.20260602~git.3476902+dfsg-4
versioned links
  • 146.20260602~git.3476902+dfsg-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 146.20260602~git.3476902+dfsg-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 146.20260602~git.3476902+dfsg-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libskia-dev
  • libskia146
action needed
3 security issues in sid high

There are 3 open security issues in sid.

3 important issues:
  • CVE-2026-17771: Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
  • CVE-2026-19173: Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-79020: Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (Chromium security severity: Medium)
Created: 2026-09-04 Last update: 2026-09-05 18:02
24 security issues in forky high

There are 24 open security issues in forky.

24 important issues:
  • CVE-2026-15766: Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-15774: Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-16417: Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-17653: Use after free in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
  • CVE-2026-17702: Inappropriate implementation in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-17712: Race in Skia in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-17745: Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
  • CVE-2026-17757: Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
  • CVE-2026-17771: Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
  • CVE-2026-17914: Side-channel information leakage in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
  • CVE-2026-17992: Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
  • CVE-2026-19154: Use after free in Skia in Google Chrome on Android prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
  • CVE-2026-19160: Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-19161: Uninitialized Use in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-19173: Out of bounds write in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-19176: Use after free in Skia in Google Chrome prior to 151.0.7922.109 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-76041: Information leak in Skia in Google Chrome prior to 151.0.7922.169 allowed a remote attacker to potentially bypass web origin policy via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-78914: Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
  • CVE-2026-79020: Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially read memory inside the sandbox via a crafted media file. (Chromium security severity: Medium)
  • CVE-2026-79112: Out of bounds read in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Low)
  • CVE-2026-79144: Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
  • CVE-2026-79147: Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)
  • CVE-2026-84359: Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
  • CVE-2026-85049: Use after free in Skia in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)
Created: 2026-09-01 Last update: 2026-09-05 18:02
testing migrations
  • excuses:
    • Migration status for libskia (146.20260602~git.3476902+dfsg-2 to 146.20260602~git.3476902+dfsg-4): BLOCKED: Maybe temporary, maybe blocked but Britney is missing information (check below)
    • Issues preventing migration:
    • ∙ ∙ Missing build on amd64
    • ∙ ∙ Missing build on i386
    • ∙ ∙ Missing build on riscv64
    • ∙ ∙ Autopkgtest deferred on amd64: missing arch:amd64 build
    • ∙ ∙ Autopkgtest deferred on i386: missing arch:i386 build
    • ∙ ∙ Autopkgtest deferred on riscv64: missing arch:riscv64 build
    • ∙ ∙ Autopkgtest for skia-pathops: arm64: Test triggered, armhf: Test triggered, ppc64el: Test triggered
    • ∙ ∙ Autopkgtest for storm-lang: arm64: Test triggered
    • ∙ ∙ Lintian check waiting for test results on riscv64, amd64, i386 - info
    • ∙ ∙ Reproducibility check deferred on amd64: missing builds - info
    • ∙ ∙ Reproducibility check waiting for results on arm64 - info
    • ∙ ∙ Reproducibility check deferred on i386: missing builds - info
    • ∙ ∙ Too young, only 1 of 5 days old
    • Additional info (not blocking):
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/libs/libskia.html
    • ∙ ∙ Reproduced on armhf - info
    • Not considered
news
[rss feed]
  • [2026-09-05] Accepted libskia 146.20260602~git.3476902+dfsg-4 (source) into unstable (Filip Strömbäck)
  • [2026-09-02] Accepted libskia 146.20260602~git.3476902+dfsg-3 (source) into unstable (Filip Strömbäck)
  • [2026-07-08] libskia 146.20260602~git.3476902+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2026-07-03] Accepted libskia 146.20260602~git.3476902+dfsg-2 (source) into unstable (Filip Strömbäck)
  • [2026-07-02] Accepted libskia 146.20260602~git.3476902+dfsg-1 (source) into unstable (Filip Strömbäck)
  • [2026-06-04] libskia 146.20260414~git.ef5f213+dfsg-5 MIGRATED to testing (Debian testing watch)
  • [2026-05-29] Accepted libskia 146.20260414~git.ef5f213+dfsg-5 (source) into unstable (Filip Strömbäck)
  • [2026-05-26] libskia 146.20260414~git.ef5f213+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2026-05-19] Accepted libskia 146.20260414~git.ef5f213+dfsg-4 (source) into unstable (Filip Strömbäck)
  • [2026-05-18] libskia 146.20260414~git.ef5f213+dfsg-3 MIGRATED to testing (Debian testing watch)
  • [2026-05-08] Accepted libskia 146.20260414~git.ef5f213+dfsg-3 (source) into unstable (Filip Strömbäck)
  • [2026-05-07] Accepted libskia 146.20260414~git.ef5f213+dfsg-2 (source) into unstable (Filip Strömbäck)
  • [2026-05-05] libskia 146.20260414~git.ef5f213+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2026-04-29] Accepted libskia 146.20260414~git.ef5f213+dfsg-1 (source) into unstable (Filip Strömbäck)
  • [2026-04-06] libskia 146.20260311+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2026-03-31] Accepted libskia 146.20260311+dfsg-4 (source) into unstable (Filip Strömbäck)
  • [2026-03-30] Accepted libskia 146.20260311+dfsg-3 (source) into unstable (Filip Strömbäck)
  • [2026-03-30] Accepted libskia 146.20260311+dfsg-2 (source) into unstable (Filip Strömbäck)
  • [2026-03-29] Accepted libskia 146.20260311+dfsg-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Filip Strömbäck)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 146.20260602~git.3476902+dfsg-2

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing