Your message dated Sun, 09 Aug 2026 17:38:44 +0000
with message-id <[email protected]>
and subject line Bug#1143968: fixed in kakoune 2026.05.21-1
has caused the Debian Bug report #1143968,
regarding kakoune: CVE-2026-48120
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143968: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143968
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: kakoune
Version: 2024.05.18-2
Severity: grave
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for kakoune.

I think this would be no-dsa in principle as needing to edit an
untrusted file to be auto restored. But raising it to RC level as this
shoul be fixed for forky and across down to trixie so far we have only
the 2024.05.18-2 based version.

CVE-2026-48120[0]:
| Kakoune is a code editor. Prior to version 2026.05.21, the bundled,
| enabled by default, `autorestore.kak` script can be exploited by
| malicious backup files leading to arbitrary kakoune and shell
| commands being executed by simply opening a file. Kakoune 2026.05.21
| fixes the issue. As a workaround, add `autorestore-disable` to the
| user kakrc will disable the autorestore feature.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48120
    https://www.cve.org/CVERecord?id=CVE-2026-48120
[1] https://github.com/mawww/kakoune/security/advisories/GHSA-h99r-h8cp-vwcq
[2] 
https://github.com/mawww/kakoune/commit/25c7b13b244fd1ddacc63ecfe1784b5ebc2ba825

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: kakoune
Source-Version: 2026.05.21-1
Done: Peter Pentchev <[email protected]>

We believe that the bug you reported is fixed in the latest version of
kakoune, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Peter Pentchev <[email protected]> (supplier of updated kakoune package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 09 Aug 2026 20:10:04 +0300
Source: kakoune
Architecture: source
Version: 2026.05.21-1
Distribution: unstable
Urgency: medium
Maintainer: Peter Pentchev <[email protected]>
Changed-By: Peter Pentchev <[email protected]>
Closes: 1143968
Changes:
 kakoune (2026.05.21-1) unstable; urgency=medium
 .
   * Declare compliance with Policy 4.7.4, drop the implied Priority: optional.
   * Refresh the debputy-style formatting.
   * Convert the watch file to version 5 of the format.
   * Add Salsa CI configuration.
   * New upstream release:
     - includes the fix for CVE-2026-48120; Closes: #1143968
     - drop the 01-typos patch
     - drop the 09-parallel-dirs patch, integrated upstream
     - refresh patch line numbers
     - add the 09-sizeof-char-ptr patch to fix the 32-bit FTBFS
   * Switch back to debhelper-compat now that debhelper 14 is out.
Checksums-Sha1:
 792fa73327d3990670fb7247cdd9bd0ab18ac9e5 2139 kakoune_2026.05.21-1.dsc
 69aff67b109e7f9cffef7013fe9ed577ce0b9b8c 798200 kakoune_2026.05.21.orig.tar.gz
 f78607ee1a1f8185b28174311b04e51b9034ca70 7604 
kakoune_2026.05.21-1.debian.tar.xz
Checksums-Sha256:
 45bb1b1d918580e4a2cc11d072c15bcb3688e74e125b9e09dc450a5bc7b18a7c 2139 
kakoune_2026.05.21-1.dsc
 7ef778bd199e05977841e6f69aad2bee6cd58fb23b0e4bc265d012d42de17580 798200 
kakoune_2026.05.21.orig.tar.gz
 5ba0eb1d574082d39d54073976f9a3000ccea81abc9dd63a65cad86e3c900772 7604 
kakoune_2026.05.21-1.debian.tar.xz
Files:
 28ebd8b90cd61df5f2438d1b237ee05a 2139 editors optional kakoune_2026.05.21-1.dsc
 138ef4b0caa00710cb005ca371be756d 798200 editors optional 
kakoune_2026.05.21.orig.tar.gz
 05b9b6f2560266775b274978a2bfef3c 7604 editors optional 
kakoune_2026.05.21-1.debian.tar.xz

-----BEGIN PGP SIGNATURE-----

iQJEBAEBCgAuFiEELuenpRf8EkzxFcNUZR7vsCUn3xMFAmp4tVMQHHJvYW1AZGVi
aWFuLm9yZwAKCRBlHu+wJSffEySLD/9p3DszXPycOPWW7hr9vLMjdqWPlE5FuqwS
x0OP3ersErcBXBUxu8phMYx0Z4Lf1fWn/nU+dVk2AxPXhVB0bkQbKuzXbO8BEhb3
v6w4LR7rlJ8mYn0UdpTHG8TJ+vP/cicMxZTWA+LTymDyJrkxRoi8uoOi7uWjJdHL
2fC8ZcET/bkGMrIngdQb6uB9UMxcWFTTHsPxZzr5GrlMo7xgeotfP/ziVYp2xuev
wc+nLFld1HwGtanJNHxqE57H42lRTL00BNJXneeW6AUn7C4/mRAukgcrXwYYPil4
iHShaXeHPALcwV/KdVYTmGgXL3gsOem7a8MNGf+TRrEQuxUmkbqfySfiD9GAoSK4
AC13bE6oGAQtID1jMziAkYp7iHio4CfdXyNt1q7AyiXUS6WfKv9oSxYf/TkeGTUk
POwSmVG2nbkYZfm3OvFYulFdJUeU8M4Ax0g1USMaEViGDu0eMsqKAByGGmTJCl2P
BH1ewCiW2fuW9BO/Rvy/B6IWJHwMUJ3gLM+AWqGfXYcqcG07td74EGjtwwHJhxtv
K8iZSLJA7jSDQ7uusd2ZgFxBmzhxnYWmHbLOoZOOWHYdHrAZwH5ztuGoV0lo0JV/
dmuk5D8jgFQf1NqJ7XfkIFyXqFKUTnJ/5eNuo+qD5+WtLdk2ex8Y87nRSGdM85F4
3IXAdI1GNw==
=utgG
-----END PGP SIGNATURE-----

Attachment: pgpyA4XOoKYUn.pgp
Description: PGP signature


--- End Message ---

Reply via email to