Your message dated Sun, 02 Aug 2026 11:33:57 +0000
with message-id <[email protected]>
and subject line Bug#1134567: fixed in docker-registry 2.8.3+ds1-3
has caused the Debian Bug report #1134567,
regarding docker-registry: CVE-2026-33540 and CVE-2026-35172
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1134567: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1134567
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: src:docker-registry
Version: 2.8.3+ds1-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected]

Hi,

The security tracker currently lists docker-registry as unfixed for two
upstream distribution vulnerabilities fixed in upstream 3.1.0:

* CVE-2026-33540 / GHSA-3p65-76g6-3w7r
  Pull-through cache credential exfiltration via an unvalidated
  WWW-Authenticate bearer realm.

  Advisory:
  
https://github.com/distribution/distribution/security/advisories/GHSA-3p65-76g6-3w7r

  The advisory lists affected versions as <= 3.0.0 and patched versions
  as >= 3.1.0. Debian currently has 2.7.1+ds2-7+deb11u1 in bullseye,
  2.8.2+ds1-1 in bookworm, and 2.8.3+ds1-2 in trixie/forky/sid.

  I checked the current sid source, 2.8.3+ds1-2. The vulnerable flow
  appears present:

  - registry/proxy/proxyauth.go:getAuthURLs appends the bearer realm
    from the upstream WWW-Authenticate challenge.
  - registry/client/auth/session.go:fetchToken parses that realm and
    fetchTokenWithBasicAuth sends configured credentials to it.

* CVE-2026-35172 / GHSA-f2g3-hh2r-cwgc
  Stale blob access resurrection via repo-scoped Redis descriptor cache
  invalidation.

  Advisory:
  
https://github.com/distribution/distribution/security/advisories/GHSA-f2g3-hh2r-cwgc

  The advisory lists affected versions as <= 3.0.x and <= 2.8.x when
  redis blob descriptor cache and delete are both enabled, and patched
  versions as >= 3.1.0.

  I checked the current sid source, 2.8.3+ds1-2. The relevant Redis cache
  code appears present:

  - registry/storage/cache/redis/redis.go has
    repositoryScopedRedisBlobDescriptorService.Clear.
  - That method checks repository membership and then calls
    rsrbds.upstream.Clear(ctx, dgst), matching the upstream advisory's
    vulnerable invalidation path.

Regards,
James

--- End Message ---
--- Begin Message ---
Source: docker-registry
Source-Version: 2.8.3+ds1-3
Done: Reinhard Tartler <[email protected]>

We believe that the bug you reported is fixed in the latest version of
docker-registry, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Reinhard Tartler <[email protected]> (supplier of updated docker-registry 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 02 Aug 2026 12:23:44 +0200
Source: docker-registry
Architecture: source
Version: 2.8.3+ds1-3
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <[email protected]>
Changed-By: Reinhard Tartler <[email protected]>
Closes: 1134567
Changes:
 docker-registry (2.8.3+ds1-3) unstable; urgency=medium
 .
   * Team upload.
 .
   [ Reinhard Tartler ]
   * Backport CVE fixes from upstream 3.1.1
     - CVE-2026-33540: bind proxy-mode bearer realms to the upstream trust
       boundary so credentials are never sent to an attacker-controlled
       realm. Closes: #1134567
     - CVE-2026-35172: fully revoke repository-scoped blob descriptors in
       the Redis cache so deleted blobs cannot be resurrected from stale
       cache entries. Closes: #1134567
     - Add golang-golang-x-net-dev build dependency for
       golang.org/x/net/publicsuffix
 .
   [ Luca Boccassi ]
   * Install and use sysusers.d/tmpfiles.d configuration files in place
     of the manual docker-registry.postinst maintainer script.
Checksums-Sha1:
 c8f0a175aebfd2ec780eec6cffa6896adbded20a 3349 docker-registry_2.8.3+ds1-3.dsc
 4135c301246db360e71f53efbffc391b57dca732 13076 
docker-registry_2.8.3+ds1-3.debian.tar.xz
 9b0c50db8d097695281468a5d8ab393139e82acc 2813908 
docker-registry_2.8.3+ds1-3.git.tar.xz
 d9425ac7b5ee92c8c09344298aeedc071bc592e1 17600 
docker-registry_2.8.3+ds1-3_source.buildinfo
Checksums-Sha256:
 a23a7b47497e09ba5730f8d8e45561fad9af304dd47a72645b2338fa734fa35a 3349 
docker-registry_2.8.3+ds1-3.dsc
 0b4cfba0763aa683f8a1ed63ad61104e0342486bebb006fc725453d99121fa12 13076 
docker-registry_2.8.3+ds1-3.debian.tar.xz
 d3ad6df77c821fd842fd18df3ab09c4bbd690b0ad2994a3c77d0a5d05a16a5c8 2813908 
docker-registry_2.8.3+ds1-3.git.tar.xz
 35e00154f8545243d4ac8db7c5419b81351877b49d58d564653435a2deda98e3 17600 
docker-registry_2.8.3+ds1-3_source.buildinfo
Files:
 3b303eddbcd1af0bc557d13459052bc5 3349 utils optional 
docker-registry_2.8.3+ds1-3.dsc
 4911f2dff470e33fa5bd4390acf529cd 13076 utils optional 
docker-registry_2.8.3+ds1-3.debian.tar.xz
 ddd412d90787e121ba40e8d89e3e7e75 2813908 utils optional 
docker-registry_2.8.3+ds1-3.git.tar.xz
 1b488b89e01522aeb76bf515d0d147d1 17600 utils optional 
docker-registry_2.8.3+ds1-3_source.buildinfo
Git-Tag-Info: tag=56df79973aa9346ec3730a3c8e53665bfe9f95c2 
fp=30de7d1763ab9452c7e0825049a76977942826cb
Git-Tag-Tagger: Reinhard Tartler <[email protected]>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpvKCcACgkQYG0ITkaD
wHlLGRAA0wNrTgkTg0Frch2/YRPHkk8ip8xQrOXELoiMhZ3oBTmcZZ6DadyQOiyM
HW2bhoC0JQtbaoRGUEpMOP6KzKrcHjaXEpQzpCRxspE+TvSQ4D9txvdhBcNoH9s0
ot/WIhjYGYUhj714HWYhWsIBHxEMA6QvmIfEJMBcLHGbDKtKYVV0m2XsHBjPM6Di
jKeN60+OyfrkabdSB421YNn6SJhk27bEA8FoKRMcvkLSNYqH4DzPL+b7YzBoXl0e
aAXY3oWaEI9F/N9LgdOYH3ZxQq8GsP7ptc7bcsIX7mV0JJs/p9Q5Sbegk4lurRZv
vvjtzxKprgTxGOSAFg5N5IaLkKpXesMuhCb0ZlaYt8yVWWdbHxUJHNPFU66MgOQ7
ah/NjkkTSiFWqcNv5j77BiD9X0QNrC7VQvgMr046Zki3dKIhoh23VQsqH9UovO+q
FHLj9J1G5pi37E5WCCLKDwTtooXIItt8eKyWnPBhBepeGinKIYDouKWEvBLrnw6C
w2AIGR9QLtPFmOkZ3+0WVTDztqX119eS8Vgj+n/eYqS1rzqTwIa6uXDCX2LOuwBD
eAqXG2DvREHyeuFHo42RjnKSNJQhvyQPUaLJyLgcRy62dAMWkZ4dS/1WVqI4jopD
NDshYu5PEn0dsivsl6Q3GFvpky4mmIXp5LL1aUTbWggh8uCq3Xc=
=7t2j
-----END PGP SIGNATURE-----

Attachment: pgp_axew941CY.pgp
Description: PGP signature


--- End Message ---

Reply via email to