Several issues have been found in rlottie, a library for rendering vector based animations and art. Most of these CVEs have been already fixed by Fix-crash-on-invalid-data.patch in a previous upload. The remaining boundary check has now been fixed as well. For Debian 11 bullseye, these problems have been fixed in version

Source: Debian 11 rlottie Critical Boundary Check Issue DLA-4474-1 CVE-2025-0634