CVE-2026-2314
Overview
Files Changed
DEPSthird_party/crabbyavif/README.chromiumthird_party/crabbyavif/src
Patch
From 4e749ba7969e10fa31d32488e33c5b28faf922a4 Mon Sep 17 00:00:00 2001 From: Vignesh Venkat <[email protected]> Date: Mon, 09 Mar 2026 09:00:48 -0700 Subject: [PATCH] [M138] Roll src/third_party/crabbyavif/src/ eb88302..a103c0d (1 commit) https://chromium.googlesource.com/external/github.com/webmproject/CrabbyAvif.git/+log/eb88302..a103c0d 26-01-27 [email protected] image: Remove check on allocation Bug: 478560268 Change-Id: I15e840311eb911179dd54f3a5782e1f35030ddeb Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7542337 Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7543288 Commit-Queue: Vignesh Venkat <[email protected]> Reviewed-by: James Zern <[email protected]> Cr-Commit-Position: refs/branch-heads/7207@{#6} Cr-Branched-From: 1781c8a9593964a76b12e107d4e3acc66fb42e3c-refs/heads/main@{#1466726} --- diff --git a/DEPS b/DEPS index 81e457da..4ddf2b6 100644 --- a/DEPS +++ b/DEPS @@ -451,7 +451,7 @@ # Three lines of non-changing comments so that # the commit queue can handle CLs rolling crabbyavif # and whatever else without interference from each other. - 'crabbyavif_revision': 'eb883022a5886739f07f0241f918e2be97d65ff0', + 'crabbyavif_revision': 'a103c0de433f7a50927f224d5c9790e899e52b9b', # Three lines of non-changing comments so that # the commit queue can handle CLs rolling Speedometer main # and whatever else without interference from each other. diff --git a/third_party/crabbyavif/README.chromium b/third_party/crabbyavif/README.chromium index 919d447..0c1cffc 100644 --- a/third_party/crabbyavif/README.chromium +++ b/third_party/crabbyavif/README.chromium @@ -2,7 +2,7 @@ Short Name: crabbyavif URL: https://github.com/webmproject/CrabbyAvif Version: N/A -Revision: eb883022a5886739f07f0241f918e2be97d65ff0 +Revision: a103c0de433f7a50927f224d5c9790e899e52b9b License: Apache-2.0 License File: LICENSE Security Critical: yes diff --git a/third_party/crabbyavif/src b/third_party/crabbyavif/src index eb88302..a103c0d 160000 --- a/third_party/crabbyavif/src +++ b/third_party/crabbyavif/src @@ -1 +1 @@ -Subproject commit eb883022a5886739f07f0241f918e2be97d65ff0 +Subproject commit a103c0de433f7a50927f224d5c9790e899e52b9b
Original Bug Report
blink_avif_decoder_fuzzer: Heap-buffer-overflow in InterpolateRow_Any_AVX2
Detailed Report: https://clusterfuzz.com/testcase?key=5869883250114560
Fuzzing Engine: centipede Fuzz Target: blink_avif_decoder_fuzzer Job Type: centipede_chrome_asan Platform Id: linux
Crash Type: Heap-buffer-overflow WRITE 1 Crash Address: 0x782a69fe8f80 Crash State: InterpolateRow_Any_AVX2 libyuv::ScalePlaneBilinearUp ScalePlane
Sanitizer: address (ASAN)
Recommended Security Severity: High
Regressed: https://clusterfuzz.com/revisions?job=centipede_chrome_asan&range=1567088:1567158
Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5869883250114560
Issue filed automatically.
See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for instructions on reproducing this bug locally.