google / google/brotli

Can upstream help to backport CVE-2025-6176 fix for 1.0.9 release?

Open
#1,411 4 comments 1 reaction 0 assignees View on GitHub
Dominant language
TypeScript
Stars
14.9k
Forks
1.4k
Avg merge
4d 20h
Merged PRs (30d)
9

Description

Hi,
I see that brotli-1.0.9 is C++ code and later releases are pure C code.
We saw CVE-2025-6176 [fix](https://github.com/google/brotli/pull/1234/files) in 1.2.0 release but there are still many linux [distributions](https://repology.org/project/brotli/versions) which are using brotli-1.0.9 release.
Is it possible for upstream to provide this CVE fix patch release for brotli-1.0.9 ?

Contributor guide

Open the contributing guide

Research direction

Start by reviewing the CVE-2025-6176 fix in upstream pull request #1234 and compare it with the C++ sources in brotli-1.0.9. Check the project's release or backport process and determine whether the fix applies cleanly to that version. Done means a reviewed patch or patch release is available for distributions still using 1.0.9.

Written by the indexing model from the issue text.

Assessment

Tech stack
c, cpp
Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.