Medium severity6.5NVD Advisory· Published Feb 2, 2020· Updated Jun 17, 2026
CVE-2019-20446
CVE-2019-20446
Description
In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested patterns can cause denial of service when passed to the library for processing. The attacker constructs pattern elements so that the number of final rendered objects grows exponentially.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
24- GNOME/librsvgdescription
cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gnome:librsvg:*:*:*:*:*:*:*:*range: <2.40.21
- (no CPE)range: <2.46.2
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*+ 1 more
- cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- osv-coords14 versionspkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP1pkg:rpm/almalinux/librsvg2pkg:rpm/almalinux/librsvg2-develpkg:rpm/almalinux/librsvg2-toolspkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Desktop%20Applications%2015%20SP1pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP4pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/librsvg&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP1pkg:rpm/opensuse/librsvg&distro=openSUSE%20Leap%2015.1
< 2.42.8-3.3.1+ 13 more
- (no CPE)range: < 2.42.8-3.3.1
- (no CPE)range: < 2.42.7-4.el8
- (no CPE)range: < 2.42.7-4.el8
- (no CPE)range: < 2.42.7-4.el8
- (no CPE)range: < 2.42.8-3.3.1
- (no CPE)range: < 2.42.8-3.3.1
- (no CPE)range: < 2.40.21-5.9.1
- (no CPE)range: < 2.40.21-5.9.1
- (no CPE)range: < 2.40.21-5.9.1
- (no CPE)range: < 2.40.21-5.9.1
- (no CPE)range: < 2.40.21-5.9.1
- (no CPE)range: < 2.40.21-5.9.1
- (no CPE)range: < 2.42.8-3.3.1
- (no CPE)range: < 2.42.8-lp151.3.3.1
Patches
Vulnerability mechanics
References
7- lists.opensuse.org/opensuse-security-announce/2020-03/msg00024.htmlnvdMailing ListThird Party Advisory
- gitlab.gnome.org/GNOME/librsvg/issues/515nvdVendor Advisory
- lists.debian.org/debian-lts-announce/2020/07/msg00016.htmlnvdMailing ListThird Party Advisory
- security.netapp.com/advisory/ntap-20221111-0004/nvdThird Party Advisory
- usn.ubuntu.com/4436-1/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6IOHSO6BUKC6I66J5PZOMAGFVJ66ZS57/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X3B5RWJQD5LA45MYLLR55KZJOJ5NVZGP/nvd
News mentions
0No linked articles in our index yet.