Bug 34388 - gdk-pixbuf2.0 new security issue CVE-2025-6199
Summary: gdk-pixbuf2.0 new security issue CVE-2025-6199
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-06-23 16:33 CEST by Nicolas Salguero
Modified: 2025-06-27 07:45 CEST (History)
3 users (show)

See Also:
Source RPM: gdk-pixbuf2.0-2.42.10-2.1.mga9
CVE: CVE-2025-6199
Status comment: Patch available from Debian and upstream


Attachments

Nicolas Salguero 2025-06-23 16:33:37 CEST

Status comment: (none) => Patch available from Debian and upstream
CVE: (none) => CVE-2025-6199
Whiteboard: (none) => MGA9TOO
Source RPM: (none) => gdk-pixbuf2.0-2.42.12-2.mga10.src.rpm, gdk-pixbuf2.0-2.42.10-2.1.mga9.src.rpm

Comment 1 Lewis Smith 2025-06-24 22:06:01 CEST
Easy fix.
DavidG has already done Cauldron. Needs doing for M9.

Assignee: bugsquad => pkg-bugs

katnatek 2025-06-25 04:43:41 CEST

Source RPM: gdk-pixbuf2.0-2.42.12-2.mga10.src.rpm, gdk-pixbuf2.0-2.42.10-2.1.mga9.src.rpm => gdk-pixbuf2.0-2.42.10-2.1.mga9
Version: Cauldron => 9
Whiteboard: MGA9TOO => (none)
Assignee: pkg-bugs => j.alberto.vc

Comment 2 katnatek 2025-06-25 04:53:54 CEST Comment hidden (obsolete)

Assignee: j.alberto.vc => qa-bugs

Comment 3 Herman Viaene 2025-06-25 11:27:53 CEST
Are you sure these are the new versions??? The ones listed are already installed on my laptop.

CC: (none) => herman.viaene

Comment 4 Nicolas Salguero 2025-06-25 11:31:57 CEST
RPMS:
gdk-pixbuf2.0-2.42.10-2.2.mga9
lib(64)gdk_pixbuf-gir2.0-2.42.10-2.2.mga9
lib(64)gdk_pixbuf2.0-devel-2.42.10-2.2.mga9
lib(64)gdk_pixbuf2.0_0-2.42.10-2.2.mga9

SRPM:
gdk-pixbuf2.0-2.42.10-2.2.mga9

Status: NEW => ASSIGNED

Comment 5 katnatek 2025-06-25 12:11:10 CEST
Thank you Nicolas
Comment 6 Herman Viaene 2025-06-25 14:15:57 CEST
MGA9-64 server Plasma Wayland on Compaq H000SB
No installation issues.
Ref bugs 22399 and 33223 fr some tests.
$ convert IMG_1251.jpg -colorspace Gray grey.jpg
grey image is as expected and shows well in gwenview.
Run audacity, do operations on an imported.wav file, all works OK.
AFAICS this is good to go.

Whiteboard: (none) => MGA9-64-OK

Comment 7 Thomas Andrews 2025-06-26 22:20:56 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

katnatek 2025-06-27 05:51:06 CEST

Keywords: (none) => advisory

Comment 8 Mageia Robot 2025-06-27 07:45:00 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0198.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED


Note You need to log in before you can comment on or make changes to this bug.