Dear security team, concerning CVE-2026-59986 https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-jgjf-7fwf-f3c7 and CVE-2026-61547 https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh
Upstream's v0.17.0 fixing both had been uploaded to unstable recently and has in the meantime already migrated to testing, cf. https://tracker.debian.org/pkg/librabbitmq Unfortunately, at the time of upstream's v0.17.0 release, the CVE identifiers were not yet known, so they were not part of the changelog. I have since added them for reference, cf. https://salsa.debian.org/debian/librabbitmq/-/commit/1e6e7e0d8809f0a2d79110235fe177a94371a588 Here now come the patches for Trixie, backported and reduced to the essentials for fixing the vulnerabilities. Given how few changes upstream's latest releases show, I don't see much risk in just applying them, cf. https://github.com/alanxz/rabbitmq-c/compare/v0.15.0...v0.17.0 So I just prepared the patches and uploaded them to Salsa, cf. https://salsa.debian.org/debian/librabbitmq/-/commits/debian/trixie?ref_type=heads where the Pipeline was able to build the package (albeit in Sid, that is), cf. https://salsa.debian.org/debian/librabbitmq/-/pipelines/1137640 If you want to issue a DSA based on this already, please feel free to just do so. Otherwise just let me know if I should rather apply any changes. Dear LTS Team, likewise I have prepared the patches and uploaded them to Salsa for Bookworm and Bullseye, cf. https://salsa.debian.org/debian/librabbitmq/-/commits/debian/bookworm?ref_type=heads and https://salsa.debian.org/debian/librabbitmq/-/commits/debian/bullseye?ref_type=heads Please feel free to base a DLA on this, or just let me know if I should rather apply any changes. Cheers, Flo
signature.asc
Description: PGP signature
