-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4780-1 [email protected] https://www.debian.org/lts/security/ Abhijith PA September 15, 2026 https://wiki.debian.org/LTS - -------------------------------------------------------------------------
Package : urwid Version : 2.1.2-4+deb12u1 CVE ID : CVE-2026-9323 The urwid web display backend generates web session identifiers by concatenating two random.randrange(10**9) calls that use Python's Mersenne Twister PRNG, which is not cryptographically secure. The same identifier is also used as the filename of a FIFO created in the world-listable /tmp directory, so any local user on the host can list /tmp to enumerate active session tokens directly. With a valid session ID, an attacker can read the victim's terminal screen via the polling endpoint, inject keystrokes into the victim's session, and inject exit sequences or flood the FIFO to terminate or crash the session. For Debian 12 bookworm, this problem has been fixed in version 2.1.2-4+deb12u1. We recommend that you upgrade your urwid packages. For the detailed security status of urwid please refer to its security tracker page at: https://security-tracker.debian.org/tracker/urwid Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqo3ZgACgkQhj1N8u2c KO9ksQ//fVlUR7u/akjrDcMkosAn9I2Z+rZBIBcKjgw4YTbFBYI08UI/ZmwPkz97 AQtqrrXuTL3xKuwl6sUhZ28ECDxwVwkUcjwaTRkWpyFyB3jRkkXRjP9IpFhWKI7f DrV68px9c554lb1ATxVbRJ1fT5R/V2lUsA2i10Y+k0p6TKjDFnI1RXwdtA+139H/ stFCBLiLgknufl/KNVs73A8ipHWiTDpsI8wBJ6iogZj8pLkkKb/u/95vo+25rMMw MkCXk3GPuRFGw/k2xyis0cViDU0hFF7gA2IfqouS8mnMuhCwn5hhRFnbnm7qeRa4 5CYaM/6kOQOkLTX4coIbzraax33NZ7VTY3nwUQLDn5FnC7EgVmjNv0awdpJft/Hq Wi2+Xc2om2nNRWBaPc4kEehd+h1nDxx//0PAlUSqWEih66NwupEZht7iqlSSnh8d SynIQA8If+xajHxrulbhFkDU+bSdQiYqu/1m+btwkxgYbx37+zIBSpDQrrC005Eh 0pmrKqCIwTFR6c6et6u7sjygJidxPcscR9tL1viDzDCi0Np1HZRxnbqPA8egm4uF xjrW9Km7CYM/QselHhG4a3Mg71XrdvhH5Mj8aTPEpLuUlygavUSG9BMrAxpt1aYY 9R90iimG7aj1veVInbbv57Rr1lA9bqILkiOvj94bquuIFvCx+PM= =/clh -----END PGP SIGNATURE-----
