CVE-2019-20446: Canonical Ubuntu Linux
Medium severity, CVSS 6.5. EPSS: 2.1% chance of exploitation in the next 30 days.
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 30 only; version 31 only
- Gnome Librsvg: before 2.40.21 (fixed in 2.40.21); from 2.42.0, before 2.42.8 (fixed in 2.42.8); from 2.44.0, before 2.44.16 (fixed in 2.44.16)
- Netapp Active Iq Unified Manager: affected versions not specified
- Opensuse Leap: version 15.1 only
Published 2020-02-02. Last modified 2026-06-17.