[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Debian (E)LTS report for April 2026



During the month of April 2026 and on behalf of Freexian, I worked on the
following:

libxml-parser-perl
------------------

Uploaded 2.46-2+deb11u1, 2.44-4+deb10u1 and 2.44-2+deb9u1, and issued
DLA-4522-1 and ELA-1675-1.
https://lists.debian.org/msgid-search/?m=adC6Tec0bVr84j-K@debian.org
https://www.freexian.com/lts/extended/updates/ela-1675-1-libxml-parser-perl/

  * CVE-2006-10002: Buffer overflow in parse_stream() when filehandle has
    :utf8 layer
  * CVE-2006-10003: Off-by-one heap buffer overflow in st_serial_stack()

(The backport and test work was done during the month of March, but the
updates came in early April.)

mapserver
---------

Uploaded 7.6.2-1+deb11u2, 7.2.2-1+deb10u1, and 7.0.4-2+deb9u1 and issued
DLA-4537-1 and ELA-16861-1.
https://lists.debian.org/msgid-search/?m=aeJWe2deUiwmnqTu@debian.org
https://www.freexian.com/lts/extended/updates/ela-1686-1-mapserver/

  * CVE-2026-33721: Heap-buffer-overflow write in the SLD parser

Also, updated the debdiff in os-pu bug #1131735 with the fix.

roundcube
---------

Updated custom fix for CVE-2026-35540 so it doesn't break PHP<7.1
compatibility.  Since bullseye has PHP 7.4 (and buster PHP 7.3) the
issue does not warrant a regression update for DLA-4517-1.  But the fix
will be included in a future update.
https://salsa.debian.org/roundcube-team/roundcube/-/commit/021968cea0fd16a16d8e1a565d183ac51237576a

unbound
-------

WIP to fix upstream issue https://github.com/NLnetLabs/unbound/issues/1247
and align on s-pu.  The issue does not warrant an upload to LTS on its
own, but will be included in a future update.

mediawiki
---------

Backported upstream fixes for

  * CVE-2026-34087 (OATHAuth extension): Users API leaks whether
    privileged users have their user groups disabled for lack of 2FA.
  * CVE-2026-34088: RecentChanges entries expose suppressed content via
    generated log page html.
  * CVE-2026-34093: Special:UserRights allows viewing user rights from
    private wiki.
  * CVE-2026-34095: Action=raw with Special:Mypage subpage title
    responds with "Content-Type) SECURITY: text/html" on
    ctype=text/javascript request.

Tests are still ongoing though so I didn't upload during the month of April.

dovecot
-------

Uploaded 1:2.3.13+dfsg1-2+deb11u3 and issued DLA-4556-1.
https://lists.debian.org/msgid-search/?m=afQ2DwxFPadojJqD@debian.org

   * CVE-2025-59031: No longer install decode2text.sh into dovecot-core/
     examples as the script unsafely handles zip-style attachments.
   * CVE-2025-59032: ManageSieve panic occurs with sieve-connect as a client.
   * CVE-2026-0394: Path traversal in passwd-file passdb using %d.
   * CVE-2026-27855: OTP driver is vulnerable to replay attack.
   * CVE-2026-27856: Doveadm credentials were not checked using
     timing-safe checking function.
   * CVE-2026-27857: Sending excessive parenthesis caused imap-login to
     use excessive memory.
   * CVE-2026-27858: managesieve-login can allocate large amount of
     memory during authentication.
   * CVE-2026-27859: Excessive RFC 2231 MIME parameters in email would
     cause excessive CPU usage.

(The update was uploaded on May 1st but the backport and test work was
done during April.)

Also, inform the maintainer about (relatively minor) issues with the
fixes for CVE-2026-27855 and CVE-2026-27857 as uploaded to in bookworm-
and trixie-security.  Fixes for theses issues will be applied via -pu.


Thanks to the sponsors for financing the above, and to Freexian for
coordinating!
-- 
Guilhem.

Attachment: signature.asc
Description: PGP signature


Reply to: