ECHO-c07a-bc81-6c75

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-c07a-bc81-6c75.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-c07a-bc81-6c75
Upstream
Withdrawn
2026-02-11T13:00:04Z
Published
2025-09-15T01:09:08Z
Modified
2026-09-15T03:33:36Z
Summary
Floating-point exception in pixman's combine_inner function triggered only via the stress-test developer test binary, not the runtime library. The vulnerable code is in stress-test.c which is never compiled, shipped, or installed in the libpixman-1-0 package present in Echo containers. Debian marks this as "unimportant" with note "Crash in test tool, no security impact." No upstream fix after 2.5+ years. https://security-tracker.debian.org/tracker/CVE-2023-37769
Details
References

Affected packages

Echo / pixman

Package

Name
pixman
Purl
pkg:deb/echo/pixman

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.44.0-3

Database specific

source
"https://advisory.echohq.com/osv/ECHO-c07a-bc81-6c75.json"