Your message dated Sat, 08 Aug 2026 09:34:18 +0000
with message-id <[email protected]>
and subject line Bug#1143904: fixed in golang-github-go-git-go-git-v6 
6.0.0~alpha.5-1
has caused the Debian Bug report #1143904,
regarding golang-github-go-git-go-git-v6: CVE-2026-71556 CVE-2026-71557
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143904: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143904
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: golang-github-go-git-go-git
Version: 5.19.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: clone -1 -2
Control: reassign -2 src:golang-github-go-git-go-git-v6 6.0.0~alpha.4-2
Control: retitle -2 golang-github-go-git-go-git-v6: CVE-2026-71556 
CVE-2026-71557

Hi,

The following vulnerabilities were published for golang-github-go-git-go-git.

CVE-2026-71556[0]:
| go-git is an extensible git implementation library written in pure
| Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations
| (including checkout, status, and add) resolve symbolic links inside
| the working tree without confining resolution to the worktree
| boundary, so a maliciously crafted repository containing a symlink
| can cause go-git to read from or write to files outside the intended
| working directory when the repository is cloned and its worktree
| operations are used. Versions 5.19.2 and 6.0.0-alpha.5.


CVE-2026-71557[1]:
| go-git is an extensible git implementation library written in pure
| Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not
| sanitized before being used to construct on-disk paths under the
| reference storage directory, so a maliciously crafted reference name
| (for example containing directory-traversal sequences) can cause go-
| git to write files outside the intended reference storage directory.
| Versions 5.19.2 and 6.0.0-alpha.5 fix the issue.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-71556
    https://www.cve.org/CVERecord?id=CVE-2026-71556
[1] https://security-tracker.debian.org/tracker/CVE-2026-71557
    https://www.cve.org/CVERecord?id=CVE-2026-71557

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: golang-github-go-git-go-git-v6
Source-Version: 6.0.0~alpha.5-1
Done: Daniel Baumann <[email protected]>

We believe that the bug you reported is fixed in the latest version of
golang-github-go-git-go-git-v6, which is due to be installed in the Debian FTP 
archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Daniel Baumann <[email protected]> (supplier of updated 
golang-github-go-git-go-git-v6 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 08 Aug 2026 11:10:25 +0200
Source: golang-github-go-git-go-git-v6
Architecture: source
Version: 6.0.0~alpha.5-1
Distribution: sid
Urgency: medium
Maintainer: Daniel Baumann <[email protected]>
Changed-By: Daniel Baumann <[email protected]>
Closes: 1143904
Changes:
 golang-github-go-git-go-git-v6 (6.0.0~alpha.5-1) sid; urgency=medium
 .
   * Merging upstream version 6.0.0~alpha.5:
     - fixes Improper Link Resolution Before File Access ('Link Following')
       [CVE-2026-71556] (Closes: #1143904).
     - fixes Improper Limitation of a Pathname to a Restricted Directory
       ('Path Traversal') [CVE-2026-71557] (Closes: #1143904).
Checksums-Sha1:
 b911370e98b55baf8a61c1bd7f7acf7cd5ebcb74 2192 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1.dsc
 6ba0bffd81b2678ed749c29bb5e9fdf548718702 765808 
golang-github-go-git-go-git-v6_6.0.0~alpha.5.orig.tar.xz
 787842aa3ab3569efb7f3efcae04c03abc20d9a9 2808 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1.debian.tar.xz
 0fa4bde9bdab02acdd4f321fabbb862fd69f1739 7518 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1_amd64.buildinfo
Checksums-Sha256:
 d4acd49d6432aa6e7ddb20697a00d44404c5a8c3c2cec715292aa001b262f33e 2192 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1.dsc
 6c3296992898bc3e8ea20d4304f4c7dff1ca50d7f60623b976e048b646efd534 765808 
golang-github-go-git-go-git-v6_6.0.0~alpha.5.orig.tar.xz
 0e11f7ce6a091c11b5ed2eefa5a968cdc3caafbab7fb8003891479d36c03b25f 2808 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1.debian.tar.xz
 d9f6ee1b3c6fce1c65a13aef69e49293bcd0411b1523cf8e6d20815938117097 7518 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1_amd64.buildinfo
Files:
 dd14f2b8f6836b2f82b20a64f0ec8fc9 2192 golang optional 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1.dsc
 fdf62feaf637716ab33f50ac16f19aeb 765808 golang optional 
golang-github-go-git-go-git-v6_6.0.0~alpha.5.orig.tar.xz
 8f9c053b6fe7003cdf9881f530dcbd32 2808 golang optional 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1.debian.tar.xz
 38f02c843a5373658aad0a1f48cb7816 7518 golang optional 
golang-github-go-git-go-git-v6_6.0.0~alpha.5-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQmmGg4gLaoSj0ERgL7tPDoCoAiLwUCanbzjgAKCRD7tPDoCoAi
LyXGAQDq9DX1py0Ap8uP4ULN7iN7vEbM4oNJGexYmu4P4OtESwEA6raHSPafIPr7
d2WKGLZCIU9o0Q0BAXaxb3iKjaQAhQM=
=IVF9
-----END PGP SIGNATURE-----

Attachment: pgpzG0MGDCPpp.pgp
Description: PGP signature


--- End Message ---

Reply via email to