Your message dated Fri, 31 Jul 2026 17:36:10 +0000
with message-id <[email protected]>
and subject line Bug#1143053: fixed in open-isns 0.103-1
has caused the Debian Bug report #1143053,
regarding open-isns: CVE-2026-55995
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1143053: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143053
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: open-isns
Version: 0.101-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for open-isns.
CVE-2026-55995[0]:
| A Double Free vulnerability in open-iscsi allows
| an unauthenticated MITM attacker to cause DoS. This issue
| affects open-iscsi: from ? through
| 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.
(note this is is really in open-isns, not open-iscsi source as in the
oficial CVE descirption, they reference to the [1] commit as fix).
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-55995
https://www.cve.org/CVERecord?id=CVE-2026-55995
[1]
https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: open-isns
Source-Version: 0.103-1
Done: Chris Hofstaedtler <[email protected]>
We believe that the bug you reported is fixed in the latest version of
open-isns, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Chris Hofstaedtler <[email protected]> (supplier of updated open-isns package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Fri, 31 Jul 2026 19:09:07 +0200
Source: open-isns
Architecture: source
Version: 0.103-1
Distribution: unstable
Urgency: medium
Maintainer: Debian iSCSI Maintainers <[email protected]>
Changed-By: Chris Hofstaedtler <[email protected]>
Closes: 1143053
Changes:
open-isns (0.103-1) unstable; urgency=medium
.
* Team upload.
* New upstream version 0.103, fixes CVE-2026-55995 (Closes: #1143053)
* d/control: set X-Style black
* Switch build system to meson. Upstream replaced the buildsystem.
This also drops building static libraries.
Checksums-Sha1:
0599816c652f03fb0240a4943f6b4d5703432c32 2380 open-isns_0.103-1.dsc
7955845c0e55d6bdd1cbbd8b709dc124c3c1e7a7 255027 open-isns_0.103.orig.tar.gz
ddb0fb54208925d98cf424916f1e7cfd2a2c036c 18516 open-isns_0.103-1.debian.tar.xz
e662bdc8a09ceed493c432632debf9e993bce5cc 9184 open-isns_0.103-1_arm64.buildinfo
Checksums-Sha256:
fcc309bcb4e15f87c308cfbd1bf94089e17549f0c0d746280b4a840c71fd1590 2380
open-isns_0.103-1.dsc
4cbbb4a0b5d75466904c7f398ff705106a116a2107a30c8dfd5ea2eba5513542 255027
open-isns_0.103.orig.tar.gz
a01892185c8728da9abc2d5b74c333bb71dc408f90a55986bfb338294b40421f 18516
open-isns_0.103-1.debian.tar.xz
2ccc83d5b300e4d3a476f1f9f484367533262912e5309f3c338bdbfbda137f46 9184
open-isns_0.103-1_arm64.buildinfo
Files:
316844ca19f875b5d956071977883948 2380 net optional open-isns_0.103-1.dsc
87c5e08bedace78ad5e2ea6113f38afe 255027 net optional
open-isns_0.103.orig.tar.gz
d53d81e2363eb264298155318e34a487 18516 net optional
open-isns_0.103-1.debian.tar.xz
3f9b3d54cda6a74b280ff19d23e86b09 9184 net optional
open-isns_0.103-1_arm64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfRrP+tnggGycTNOSXBPW25MFLgMFAmps14sACgkQXBPW25MF
LgMjXQ/+NQKP+m+hT+wDZAOzeBdbHQ6HEciY1DKPs+vowiW6WAVfzod98piKXoHg
4qnoYMex7OpzgNxayj3btbEld8LlsJX1TgZuHeCh+zEVXH5/DNIArZBPqQAvQ75j
FP8LSptl04/QF1NBdbkJXbhAx5OvvxDQTYi+cEVSUFOaOli/JTd71mZqDOU4OaLU
G7dhq5lm2Zl63HQ2UnaTwyAw7K42DNt+mnCycmKF1QBDvzrrNQvXzktVvnTLKDly
aspTzJqWUXVmW+UJjk+G+txKuG37rwdzOxI6GLS/dfpC2LJhdhnwIPY5E2e1US/y
1aGpTpHXlWZTcj7SilIdzGgH1wtp+PVpzloJFbytQ/AJdaSkSQjEu38QGXnHoNZX
QUMG9aQA1/TSaDlDezS2ps1fZwxzMFFWGIqc/XJg13+/oSrvmQLPwXREvg6GROoM
JbAX+kCfIqxP2nbYLwTmyS1zTI5QxZpE5Bl9RfIMunjm3Hl2mgfybVgG5ERociaV
z/9tIU9nQ5x1eK3T1DJM3WcG7LAB6uqH+x47kwSBYL1fFfCXyo0w9J4QupvHKBrM
zubUv9ayZ5ZBrRMzAUw9AskcyD57WDI4N/YO2TTBF11B/APTimnmqga3Ara9wk7S
AUrGW29mPx/VVUUkRz6MkF02YywqNZSflEPqqOSahpvUdm5q9S4=
=m1MK
-----END PGP SIGNATURE-----
pgpX8FHm1SIW4.pgp
Description: PGP signature
--- End Message ---