CVE-2015-5297: Pixman

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

An integer overflow issue has been reported in the general_composite_rect() function in pixman prior to version 0.32.8. An attacker could exploit this issue to cause an application using pixman to crash or, potentially, execute arbitrary code.

Affected products

  • Pixman Pixman: before 0.32.8 (fixed in 0.32.8)

Published 2019-07-31. Last modified 2026-06-17.