---
title: "CVE-2019-20446\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2019-20446?format=md
keywords: index, follow
---

# CVE-2019-20446

Publication date 2 February 2020

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**6.5 · Medium**

[Score breakdown](https://ubuntu.com/security/CVE-2019-20446?format=md#impact-score)

Toggle side navigation

## Description

In xml.rs in GNOME librsvg before 2.46.2, a crafted SVG file with nested
patterns can cause denial of service when passed to the library for
processing. The attacker constructs pattern elements so that the number of
final rendered objects grows exponentially.

[Read the notes from the security team](https://ubuntu.com/security/CVE-2019-20446?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| librsvg | 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Not affected |
| 20.04 LTS focal | Not affected |
| 19.10 eoan | Ignored end of life |
| 18.04 LTS bionic | Ignored end of standard support |
| 16.04 LTS xenial | Ignored end of standard support, was needed |
| 14.04 LTS trusty | Not in release |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2019-20446?format=md#patch-details)

## Notes

---

### [mdeslaur](https://launchpad.net/~mdeslaur)

also affects older versions written in C
The fixes added to 2.40.21 cause a regression, and upstream will
not be fixing them.

---

### [rodrigo-zaiden](https://launchpad.net/~rodrigo-zaiden)

backporting the missing part of the fix from the 2.46
version (in Rust) to 2.40 (in C) is not trivial and
requires an effort for someone involved in the project.
as of 2022-11-25, there is no new commits in 2.40 branch.

---

### [ccdm94](https://launchpad.net/~ccdm94)

upstream has released a fix for this issue, and also a new version
containing said fix (2.40.21). Applying the patch recovered from
version 2.40.21 caused a regression, as per launchpad bug 1889206,
and there have been no additional commits in branch 2.40 in the
last 2 years (last commit in 2020-02-26). In issue 612, upstream
mentions that they will no longer provide fixes to branch 2.40.
They also mention the fix to the regression, available for later
versions of the code, but backporting it is not viable, as the
code has been refactored and is now in an entirely different
programming language. This mean there are no possible commits
provided that would allow a fix for the regression in releases
containing the C version of the code. Therefore, this issue will
be marked as ignored for bionic and earlier.

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| librsvg | * Upstream:   [572f95f](https://gitlab.gnome.org/GNOME/librsvg/commit/572f95f739529b865e2717664d6fefcef9493135) * Upstream:   [27f1f35](https://gitlab.gnome.org/GNOME/librsvg/commit/27f1f35557515747c423ab780d7b1a2d7a711fa1) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

6.5 · Medium

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Network |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | High |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 6.5 · Medium |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-20446)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2019-20446)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2019-20446)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2019-20446)

### Related Ubuntu Security Notices (USN)

+ [USN-4436-1](https://usn.ubuntu.com/USN-4436-1)
+ librsvg vulnerabilities
+ 27 July 2020

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2019-20446>
