Can upstream help to backport CVE-2025-6176 fix for 1.0.9 release?
- Dominant language
- TypeScript
- Stars
- 14.9k
- Forks
- 1.4k
- Avg merge
- 4d 20h
- Merged PRs (30d)
- 9
Description
Hi,
I see that brotli-1.0.9 is C++ code and later releases are pure C code.
We saw CVE-2025-6176 [fix](https://github.com/google/brotli/pull/1234/files) in 1.2.0 release but there are still many linux [distributions](https://repology.org/project/brotli/versions) which are using brotli-1.0.9 release.
Is it possible for upstream to provide this CVE fix patch release for brotli-1.0.9 ?
Contributor guide
Research direction
Start by reviewing the CVE-2025-6176 fix in upstream pull request #1234 and compare it with the C++ sources in brotli-1.0.9. Check the project's release or backport process and determine whether the fix applies cleanly to that version. Done means a reviewed patch or patch release is available for distributions still using 1.0.9.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- c, cpp
- Domain
- release, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100