Skip to content

Eclipse ThreadX GUIX v6.5.2.202603

Latest

Choose a tag to compare

@fdesbiens fdesbiens released this 02 Oct 19:12
9818c22

This release is almost entirely about the code that parses untrusted input. Nine vulnerabilities are fixed across the binary resource loader and the JPEG and PNG decoders, seven of them heap out-of-bounds writes or reads reachable by loading a crafted resource or image. GUIX's regression suite now also runs on dev rather than only on master, across every configuration, with coverage merged and gated.

We thank the independent contributors @Kimdir01, @adawn0106 and @parsley for their valuable contributions to this release.

The GUIX user guide is attached to this release as a PDF, in A4 and US Letter.

Vulnerabilities addressed

Nine vulnerabilities are fixed in 6.5.2.202603. Every one of them is reached by loading a resource or an image, so the exposure is the same in each case: a product that loads a GUIX Studio binary resource, a JPEG or a PNG it did not produce itself, from removable media or an update.

All nine affect every release up to and including 6.5.1.202602a, except CVE-2026-92449, which affects 6.3.0 onward. All are fixed in 6.5.2.202603.

Five were reported by @Kimdir01 and two by @adawn0106; the remaining two were found during an internal review of the resource loader. Every advisory but CVE-2026-92449 ships with a regression test that fails without its fix. That one needs a malformed theme binary as a fixture, and the resource format reuses one magic number across its header types, so a fixture built by patching a valid theme cannot reliably place the pixelmap header; it is being produced separately.

A note on CVE-2026-91057. Its fix landed before the 6.5.1.202602a tag, but that release was a GUIX Studio installer rather than a library release, so 6.5.2.202603 is the first release in which the corrected library reaches users.

You can access advisories for previously addressed vulnerabilities here.

Highlights

The binary resource loader now knows how long its resource is

Six of the nine advisories are in the binary resource loader, and they share a cause: the loader was handed a pointer with no length, so nothing it read from the file could be checked against the extent of the resource. Sizes, glyph ranges, pixelmap indices and theme ids were all taken at face value and used to index or to reserve.

The _ext loaders now take the resource length and bound every read by it, the unbounded loaders that take no length are deprecated, and the arena the loader allocates for itself is enforced at every site that writes into it. (CVE-2026-92446, CVE-2026-91189, CVE-2026-103414, CVE-2026-92449, CVE-2026-102729)

Applications using the deprecated loaders should move to the _ext variants, which is the only way the loader can tell a truncated or crafted resource from a whole one.

Image decoder hardening

The JPEG decoder rejects marker orderings that let a second SOF0 or a truncated segment desynchronise it from its own allocation, and a zero sampling factor no longer hangs the decode. The PNG decoder rejects a duplicate IHDR after IDAT, which resized the image after its buffer had been allocated. (CVE-2026-91059, CVE-2026-92454, CVE-2026-91186)

Regression and coverage gating on dev

The regression suite now runs on dev as well as master, across all 19 build configurations rather than a subset. Coverage is collected from every instrumented configuration, merged into one report and gated on a floor, so a change that loses coverage fails rather than passes quietly. Changes to dev were previously unguarded. (#196, @fdesbiens)

Other Changes

  • Parenthesised the GX_FIXED_VAL_... macro arguments, and made the radius signed where _gx_utility_circle_point_get forms a product with it. The cast used to bind to the first token of the macro argument, so at that call site it landed on the radius rather than on the product, which is what kept an unsigned multiplication from being rejected. Results are unchanged. (#171, @parsley)
  • Removed trailing whitespace flagged by an external MISRA checker (#170, @parsley)
  • Added a check that keeps the AI disclosure comment in its one accepted form, and corrected it where it had drifted (#188, #191, @fdesbiens)
  • Stopped the release script adding a Co-authored-by trailer, which asserts an authorship an AI cannot hold (#198, @fdesbiens)
  • Gave the CI install and build steps budgets that fit the work they do, and made both caps inputs of the shared workflow template so no other product is affected (#206, #207, @fdesbiens)
  • Made the ThreadX checkout blobless, cutting it from 27 MB to under 4 MB so a slow mirror no longer costs a whole run (#204, @fdesbiens)

GUIX Studio

guix_studio_setup_version_6.5.2.202603.exe is attached to this release, together with its SHA-256 checksum.

To verify the installer on Windows:

Get-FileHash guix_studio_setup_version_6.5.2.202603.exe -Algorithm SHA256

The hash it prints should match the one in guix_studio_setup_version_6.5.2.202603.exe.sha256. That file is in sha256sum format, so with both downloaded into the same directory, sha256sum -c guix_studio_setup_version_6.5.2.202603.exe.sha256 verifies it in one step on Linux or WSL.

New Contributors

Full Changelog: v6.5.1.202602a_rel...v6.5.2.202603_rel