Your message dated Thu, 17 Sep 2026 22:20:54 +0000
with message-id <[email protected]>
and subject line Bug#1139878: fixed in python-kafka 2.0.2-13
has caused the Debian Bug report #1139878,
regarding python-kafka: CVE-2026-10142
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139878: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139878
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: python-kafka
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for python-kafka.
CVE-2026-10142[0]:
| kafka-python prior to 2.3.2 contains a denial-of-service
| vulnerability in the protocol parser that allows a malicious broker
| or machine-in-the-middle attacker to exhaust memory or hang
| connections by sending a crafted 4-byte frame length value without
| bounds validation. Attackers can send a specially crafted frame
| length through the receive_bytes() function to trigger either a
| multi-gigabyte memory allocation or an uncaught ValueError that
| leaves the connection in a broken state, causing requests to hang
| and consumers to stop heartbeating until restart.
https://github.com/dpkp/kafka-python/pull/3019
https://github.com/dpkp/kafka-python/pull/3026
Fixed by:
https://github.com/dpkp/kafka-python/commit/6e4831444f972d169cdd11f5c8d50333cea3f19b
(3.0.0)
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-10142
https://www.cve.org/CVERecord?id=CVE-2026-10142
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: python-kafka
Source-Version: 2.0.2-13
Done: Thomas Goirand <[email protected]>
We believe that the bug you reported is fixed in the latest version of
python-kafka, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Thomas Goirand <[email protected]> (supplier of updated python-kafka package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 17 Sep 2026 17:48:52 +0200
Source: python-kafka
Architecture: source
Version: 2.0.2-13
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <[email protected]>
Changed-By: Thomas Goirand <[email protected]>
Closes: 1139878
Changes:
python-kafka (2.0.2-13) unstable; urgency=medium
.
* CVE-2026-10142: the last Debian version didn't fully address the issue.
Applied upstream patch: "KafkaProtocol: validate network frame size",
backported to the legacy kafka.conn architecture of this release,
including the accompanying unit tests.
(Closes: #1139878).
Checksums-Sha1:
2a83311020dd14e78e0940b932b0da6bbd8b1ec7 2299 python-kafka_2.0.2-13.dsc
eab10dcff420d692f646edada1c081472f69bca1 13544
python-kafka_2.0.2-13.debian.tar.xz
53878c1bdd5e65f20447109610080b4b5c9293fb 8434
python-kafka_2.0.2-13_amd64.buildinfo
Checksums-Sha256:
0fb42ad31e57ed82c50ecd248bcc8dd717d486c64b493aa54f2fe9f6c1a4b956 2299
python-kafka_2.0.2-13.dsc
a52686c622e7699c378067391037e1bcedcb93d7c3bae8be0efb4e308ef0c375 13544
python-kafka_2.0.2-13.debian.tar.xz
34f912c3e8c36e7403d733b30891af1a099e0be4fed84052107810b56abe3341 8434
python-kafka_2.0.2-13_amd64.buildinfo
Files:
27dc0c6d2f87ff7b458aba19145805dc 2299 python optional python-kafka_2.0.2-13.dsc
ca473cbbcb73384ef5b06292e86fd7e4 13544 python optional
python-kafka_2.0.2-13.debian.tar.xz
1281c019d1067058936c4205d10db3be 8434 python optional
python-kafka_2.0.2-13_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqsZQAACgkQ1BatFaxr
Q/7mDg//Wj5ktme0mYLDGBUEZ3nzhDI4YcEpdS4RgHG2zsIVm2qCGhba4eRtsVvA
tn5c4js0oWKmaCXWSZlLaxkZiH4HWtZTeRQHywuDjflh87hwlTJUx+zL9QclfovM
1aGvB5hMUxRKK89gDKf/3dQFEiS8+lACLz4NI596eRReY3Z3c2PMMYVyUo7/CeAr
8lTX5iGUyE82byUNHYNmTKdO7qaVjHxQ5siBq6vs/jf8CgZ0IiaPo4frj7pIykD5
g6jT6yP/oxz2qMGLLvAriP7lR1NF86EoYQ/EVxkLzvmqgcUtvbqFXbgUoyhxXQnl
oAiJH6WjDGmSGkYILie6EZCINB31HhAPH7PiidoxrWv7Vk+TCfoopj5bC1sa1rjh
exB6iIgQe/ystCu1rd5TtsyGT37K6muGaoyJqngtgFCOnX5nQyfl/D3VZ0PNP2NB
6YNx43F16Lz9/biH14lH0iLwkiZkkayzUakDU2UeXtk6oZpPUkahnzhgu1MHRSsj
QPFbihm6rGdn/mXrX0EBaXueHXixUMLbnnClFS6TFv+8VRRpZ/b+hz04V/l7o1Cz
LA486jANuEJrm07E46H+FYdCGY9TujQq2oWM17IqwynnRrKGp6d7e+7IWxrRZzEx
wUU/Tr0nM/Avl5OP+ZG94ZBXqGc+4Dt4ysYnHguukG85ZOGW0ps=
=bDoh
-----END PGP SIGNATURE-----
pgpBKgmfh7cg_.pgp
Description: PGP signature
--- End Message ---