Your message dated Thu, 10 Sep 2026 15:07:35 +0000
with message-id <[email protected]>
and subject line Bug#1139879: fixed in opentelemetry-cpp 1.28.0-1
has caused the Debian Bug report #1139879,
regarding opentelemetry-cpp: CVE-2026-44967
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139879: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139879
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: opentelemetry-cpp
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for opentelemetry-cpp.
CVE-2026-44967[0]:
| OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior
| to release 1.27.0, the OTLP HTTP exporters (traces/metrics/logs)
| read the full HTTP response into an in-memory vector of bytes
| without a size cap. This is exploitable for memory exhaustion when
| the configured collector endpoint is attacker-controlled (or a
| network attacker can MITM the exporter connection). This
| vulnerability is fixed in opentelemetry-cpp release 1.27.0.
https://github.com/open-telemetry/opentelemetry-cpp/security/advisories/GHSA-5qhm-4rfp-qqvj
https://github.com/open-telemetry/opentelemetry-cpp/issues/3958
https://github.com/open-telemetry/opentelemetry-cpp/pull/4078
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-44967
https://www.cve.org/CVERecord?id=CVE-2026-44967
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: opentelemetry-cpp
Source-Version: 1.28.0-1
Done: Colin Watson <[email protected]>
We believe that the bug you reported is fixed in the latest version of
opentelemetry-cpp, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Colin Watson <[email protected]> (supplier of updated opentelemetry-cpp
package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 10 Sep 2026 09:29:57 +0100
Source: opentelemetry-cpp
Architecture: source
Version: 1.28.0-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Science Maintainers
<[email protected]>
Changed-By: Colin Watson <[email protected]>
Closes: 1139879
Changes:
opentelemetry-cpp (1.28.0-1) unstable; urgency=medium
.
* Team upload.
* New upstream release:
- CVE-2026-44967: Limit the size of HTTP responses to 4MiB by default
(closes: #1139879).
* Drop "Rules-Requires-Root: no", default as of dpkg-dev 1.22.13.
* Drop "Priority: optional", default as of dpkg-dev 1.22.13.
* Standards-Version: 4.7.4.
Checksums-Sha1:
828bb04e840091df7e7344cacff8564724f6e7d6 2357 opentelemetry-cpp_1.28.0-1.dsc
eed391df6eea245acffc88041c2d5ec8149ec8f1 1380604
opentelemetry-cpp_1.28.0.orig.tar.gz
387fa8fe483833f54cb2270745ff2c11e926e28f 5096
opentelemetry-cpp_1.28.0-1.debian.tar.xz
56dd528f61f064b56d2a6fc2028bf83dc8884313 8562
opentelemetry-cpp_1.28.0-1_source.buildinfo
Checksums-Sha256:
c169eef02fa37a90220a325ae50036f32cee4d26f0559a28f243a61863fe0272 2357
opentelemetry-cpp_1.28.0-1.dsc
8c359919175d77c502515f5a783907d031cc6a172e44426dbe9bee3c1532201e 1380604
opentelemetry-cpp_1.28.0.orig.tar.gz
41de0fb7ce1c72327ade32c2bebcdacd9bfe576f74a6fc209dcd922c3d592525 5096
opentelemetry-cpp_1.28.0-1.debian.tar.xz
63414265d617f8d1db5e9c8f9d9f3d3c45183b829475c38c7b4b707e843b8d5a 8562
opentelemetry-cpp_1.28.0-1_source.buildinfo
Files:
61f11399a94bd5eee3fcb91b097efd2d 2357 libs optional
opentelemetry-cpp_1.28.0-1.dsc
f87f100d577bca42f4ee6b0463381fcb 1380604 libs optional
opentelemetry-cpp_1.28.0.orig.tar.gz
2e38d3afe27da708a083fcabe8766eef 5096 libs optional
opentelemetry-cpp_1.28.0-1.debian.tar.xz
2c540b11624a3a5d9de42cbe14c66115 8562 libs optional
opentelemetry-cpp_1.28.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEErApP8SYRtvzPAcEROTWH2X2GUAsFAmqixFQACgkQOTWH2X2G
UAvvyA/9GDagHrawu9sXhF70pGSOSHi+X7L8oMo18lbofHr9Z5674jKFSQjoUX23
YJy2/cTJ7/X5DvC3LWH+iiLB+vCT+WuuruDyjpF+niC3cGYuVLg+zlhiw4aAVDua
fWr0tvptB8J+n+1JQH6J924AVS+9Abu2o9npB8Q2zxa5fIq897MiB2hEZAgc1uXY
e5TiTlkLURtIHpZ8eIV30/dCDa7aRYZzuRdpQW0lHRxUhjE/jvmCVuVQjkC401HW
tBtknZGVGkvk9PUlPluc7Fl7imb4VKwME/Kpfg69otRBvO4nkwGmZC9srTleljcR
X7rn+Xpz40Db3HVU9W6lI8HG/GN2WHkWw0RvadYhrx2cn4abfkRYa3G33jfrO46Y
103SqNM3RIMODNFMg/W21VAQ91fYJgHNYWfZefT1q0nBFwM0fmL7YnikJCMlIAlH
1J7QAehpPV6qfwaYHpFPb6qgSU65GzgMZ2bzc9UbjtgZtzTdN6Pj6U8WLk6p1I0L
h57bZ4mu0revBCiMpBK6f7w+lLxOf4snjA57+7tJkJ+pBxpRCFJT/dszRP7VV/Pb
Kl+qORpQjxPIEyWVkDjCZuZ5xmcxkoXRHpXzRJ+ExTZA2mjyhY6RRg5nO4kavdSi
MEb7nW/OQGKVlfNYhZ0idl0l9Rb7aYA8FAa1BgcW0i0CHG4shrI=
=XM4z
-----END PGP SIGNATURE-----
pgpP1kmSCch7z.pgp
Description: PGP signature
--- End Message ---
--
debian-science-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-science-maintainers