Your message dated Tue, 28 Jul 2026 22:06:38 +0000
with message-id <[email protected]>
and subject line Bug#1142831: fixed in golang-github-google-go-attestation
0.6.1-1
has caused the Debian Bug report #1142831,
regarding golang-github-google-go-attestation: CVE-2026-12681
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1142831: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142831
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: golang-github-google-go-attestation
Version: 0.6.0-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for
golang-github-google-go-attestation.
CVE-2026-12681[0]:
| Improper Validation of Specified Index, Position, or Offset in Input
| vulnerability in Google go-attestation. parseEfiSignatureList() does
| not advance the buffer past vendor bytes before reading entries. For
| hashSHA256SigGUID lists, this allows attacker-controlled vendor
| header bytes to be appended to the trusted SHA256 hash list. A
| crafted TPM event log could inject arbitrary SHA256 hashes into the
| verifier's trusted measurement database, enabling a remote
| attestation verifier to accept a compromised boot state. This issue
| affects go-attestation: through 0.6.0.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-12681
https://www.cve.org/CVERecord?id=CVE-2026-12681
[1]
https://github.com/google/go-attestation/security/advisories/GHSA-9r4w-jg96-92mv
[2]
https://github.com/google/go-attestation/commit/b6e905e7ae52937f02b5ca494dd1c6a3ac7a1003
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: golang-github-google-go-attestation
Source-Version: 0.6.1-1
Done: Simon Josefsson <[email protected]>
We believe that the bug you reported is fixed in the latest version of
golang-github-google-go-attestation, which is due to be installed in the Debian
FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Simon Josefsson <[email protected]> (supplier of updated
golang-github-google-go-attestation package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 28 Jul 2026 20:03:47 +0200
Source: golang-github-google-go-attestation
Architecture: source
Version: 0.6.1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <[email protected]>
Changed-By: Simon Josefsson <[email protected]>
Closes: 1142831
Changes:
golang-github-google-go-attestation (0.6.1-1) unstable; urgency=medium
.
* New upstream (Closes: #1142831)
- CVE-2026-12681
* Use gbp sign-tags and upstream-vcs-tag
* Standards-Version: 4.7.4
* Drop Priority: optional
* Add B-D/D golang-github-google-go-tpm-tools-dev
* Use compat 14
Checksums-Sha1:
eda82ee653b4b3bc98b176cd290a0caad79cee57 2818
golang-github-google-go-attestation_0.6.1-1.dsc
94c23057fe6d38bb22ea1a2818404e2044a080d1 228428
golang-github-google-go-attestation_0.6.1.orig.tar.xz
9ed35bc67738e144d729e93a276c0c14f5dce443 3924
golang-github-google-go-attestation_0.6.1-1.debian.tar.xz
373eb267261cac70b28e375ffc0e2858f9623707 463176
golang-github-google-go-attestation_0.6.1-1.git.tar.xz
607f1df5f6a86653010097d1971d72eb0c1e90d0 17658
golang-github-google-go-attestation_0.6.1-1_source.buildinfo
Checksums-Sha256:
3e68e00ea384126f890afd048f24af2b61bfcf0d91461f849903ad611959f325 2818
golang-github-google-go-attestation_0.6.1-1.dsc
2928245bc2610e073b36c3bfb679956f7b0f447b62745cd2f2483c03ec7a58cb 228428
golang-github-google-go-attestation_0.6.1.orig.tar.xz
b4baa0b4d313eb332a6aacf372f9f9581e5192a708767503de515424930c01e9 3924
golang-github-google-go-attestation_0.6.1-1.debian.tar.xz
6e1d744ad745c8486f0e8c4b81ebc6eb39248f466dd4220b582eb05a1397f117 463176
golang-github-google-go-attestation_0.6.1-1.git.tar.xz
54b3b53921459c3587d5d93f473acea484a65513ed7f9cad45b98f72cb86e063 17658
golang-github-google-go-attestation_0.6.1-1_source.buildinfo
Files:
90a28b6f4a6d63029c949259d967ff09 2818 golang optional
golang-github-google-go-attestation_0.6.1-1.dsc
19f4d54d9baf9755e64b69484fffc97d 228428 golang optional
golang-github-google-go-attestation_0.6.1.orig.tar.xz
c9f85a1acb3db1e91f320233b0530c8e 3924 golang optional
golang-github-google-go-attestation_0.6.1-1.debian.tar.xz
af6436319695d8a41325343afa032c32 463176 golang None
golang-github-google-go-attestation_0.6.1-1.git.tar.xz
7d2d3b31f475e48dc7605373f975c310 17658 golang optional
golang-github-google-go-attestation_0.6.1-1_source.buildinfo
Git-Tag-Info: tag=75752167ca91394dfdfaff862a2e8c391e4314d2
fp=a3cc9c870b9d310abad4cf2f51722b08fe4745a2
Git-Tag-Tagger: Simon Josefsson <[email protected]>
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmppIvUACgkQYG0ITkaD
wHmEEg/9ELHiiPebG8rpnlpmbPx5ea83JFIHrSzLjz8wnkpq8FEDX0gzH5N+Ym34
8G1QPTkiJLYvx2ChAGBLMV74hWsjpXWasWvNjgUj6ilxsbtb53uC6DhSDPY79MqQ
0WS0br3hSIoGcjtQhvXoCw4WMMNzHCZ6Lq4pjTDkLgj5vmFuuXWKA083g1YnyfIW
fP+CqjAqMJe4Vcabn0e5I7Qyv5/mpKS1FOFosYeoI1fz7qsl/HsegqGsrNmO2SMm
2fwU2wYT8Eg7Wbk64QnrVTmaqYYt5mhEOmYK00FGLm0BlcrgQKjjr/gxBf5YKITm
DzRSkK4sYi/6mtxhAF1v96DBarA+h/jkg693w6zW6w74Wy5LTX5zcWisFGVeprdH
kxl+ZrLGTcUZYeZpLjcwFzpnphD1HURt5hFP4rhmAt6oam0SHYnW7i4Z+1dwURiI
9as8EVXBa5UA2WHs2WEzezEYrbcCEEv/QzDuWgOX5tcksPjh8bNo/B+lOeR2pUhY
4ey39j5MnDttezuU6TQ/phbxCGe32ojI67+cnIMywddmdzBKFk2Mcnco0wABw99X
8YxkaABvCFFtBBmrUHRPW0yHkY+3qK0ukrrGXr93XSd9v1rfqtmDjaHw2BtmcdOb
M6GvFVCUdcL7jNUx8kd6Hq9+36s8XYTAPRL0J0z4zCft5GLjdNU=
=Znkz
-----END PGP SIGNATURE-----
pgp1vwutgLREo.pgp
Description: PGP signature
--- End Message ---