Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Graphite2 | Ubuntu | jammy | * |
| Graphite2 | Ubuntu | noble | * |
| Graphite2 | Ubuntu | questing | * |
| Graphite2 | Ubuntu | resolute | * |
| Graphite2 | Ubuntu | upstream | * |