stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
| Software | From | Fixed in |
|---|---|---|
| nothings / stb_image.h | 2.27 | 2.27.x |
| fedoraproject / fedora | 34 | 34.x |
| fedoraproject / fedora | 35 | 35.x |
| fedoraproject / fedora | 36 | 36.x |
| debian / debian_linux | 10.0 | 10.0.x |