During the month of July 2026 and on behalf of Freexian, I worked on the
following:

roundcube
---------

Uploaded 1.4.15+dfsg.1-1+deb11u10 and 1.6.5+dfsg-1+deb12u10, and issued
DLA-4693-1.
https://lists.debian.org/msgid-search/[email protected]

  * CVE-2026-54432: Stored XSS via unescaped attachment MIME type on the
    attachment-validation warning page
  * CVE-2026-54433: Zero-click stored XSS in plain-text rendering
  * CVE-2026-62641: DoS via crafted compressed-RTF size in the TNEF file
  * CVE-2026-62642: Infinite loop in TNEF decoder
  * CVE-2026-62643: SSRF bypass via malicious embedded stylesheet
  * CVE-2026-62644: Username spoofing via session data [password plugin]

For bookworm, 1.6.5+dfsg-1+deb12u10 also restores compatibility with
PHP<8 which the previous update broke.

libraw
------

Uploaded 0.20.2-1+deb11u3 and 0.20.2-2.1+deb12u2, and issued DLA-4704-1.
https://lists.debian.org/msgid-search/[email protected]

  * CVE-2026-5342: Out-of-bounds read in the decoder routine for RAW
    image files from Nikon digital cameras
  * CVE-2026-20884: Integer overflow in the decoder routine for
    deflate-compressed floating-point DNG RAW files
  * CVE-2026-20889: Heap-based buffer overflow in the thumbnail
    extraction routine for RAW image files from Sigma/Foveon X3F digital
    cameras
  * CVE-2026-21413: Heap-based buffer overflow vulnerability in the
    lossless JPEG decoder used for processing compressed RAW data from
    various camera formats
  * CVE-2026-24660: Heap-based buffer overflow vulnerability in the
    Huffman decompression routine for RAW image files from Sigma/Foveon
    X3F digital cameras

Also, file trixie-pu bug #1142984 fixing the above vulnerabilities plus

  * CVE-2026-24450: Integer overflow in the decoder routine for
    uncompressed floating-point DNG files

poppler
-------

Uploaded 20.09.0-3.1+deb11u3 and 22.12.0-2+deb12u3, and issued
DLA-4709-1.
https://lists.debian.org/msgid-search/[email protected]

  * CVE-2024-6239: pdfinfo(1) crash when using the -dests parameter
  * CVE-2025-43718: SIGSEGV via crafted PDF containing deeply nested
    structures within the metadata
  * CVE-2025-43903: Signatures with non-empty encapsulated content were
    trivially forgeable
  * CVE-2025-50420: Infinite recursion in pdfseparate(1)
  * CVE-2025-52885: Use-after-free
  * CVE-2025-52886: Integer overflow
  * CVE-2026-10118: Integer overflow in the Splash backend

For ELTS suites, the work isn't finalized yet but an ELA will be issued
shortly.


Thanks to the sponsors for financing the above, and to Freexian for
coordinating!
-- 
Guilhem.

Attachment: signature.asc
Description: PGP signature

Reply via email to