[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Please publish DLA for calibre.



Hi,

I reserved DLA-4554-1 in the security-tracker.
I let calibre in data/dla-needed.txt because there are 5 more open CVEs for bullseye.

You may also want to try the Git work-arounds from the last meeting:
Jochen suggests `--filter=tree:0` or `--filter=blob:none`
https://lists.debian.org/debian-lts/2026/04/msg00026.html

Cheers!
Sylvain

On 29/04/2026 13:28, Abhijith PA wrote:
Hello team,

Can somebody publish DLA for calibre_5.12.0+dfsg-1+deb11u4 please. My
security tracker repo is broken* at the moment.

Here is the content for mail announcement.

===

Multiple vulnerabilities have been discovered in calibre, an e-book
manager

CVE-2025-64486

     calibre does not validate filenames when handling binary assets in
     FB2 files, allowing an attacker to write arbitrary files on the
     filesystem when viewing or converting a malicious FictionBook
     file. This can be leveraged to achieve arbitrary code execution.

CVE-2026-25635

     Calibre's CHM reader contains a path traversal vulnerability that
     allows arbitrary file writes anywhere the user has write
     permissions.

CVE-2026-25636

     a path traversal vulnerability in Calibre's EPUB conversion allows
     a malicious EPUB file to corrupt arbitrary existing files writable
     by the Calibre process

CVE-2026-26064

     a path traversal vulnerability that allows arbitrary file writes
     anywhere the user has write permissions.

CVE-2026-26065

     Path Traversal through PDB readers that allow arbitrary file
     writes with arbitrary extension and arbitrary content anywhere the
     user has write permissions. Files are written in 'wb' mode,
     silently overwriting existing files. This can lead to potential
     code execution and Denial of Service through file corruption.

=====

* - My desktop copy of security-tracker have not updated since some
     time and when I do pull, I am getting timeouts and similar errors,
     which have reported in #debian-salsa.


Reply to: