---------------------------------------------------------------------------- Debian Stable Updates Announcement SUA 286-1 https://www.debian.org/ [email protected] Adam D. Barratt September 7th, 2026 ----------------------------------------------------------------------------
Upcoming Debian 13 Update (13.7) An update to Debian 13 is scheduled for Saturday, September 12th, 2026. As of now it will include the following bug fixes. They can be found in "trixie-proposed-updates", which is carried by all official mirrors. Please note that packages published through security.debian.org are not listed, but will be included if possible. Some of the updates below are also already available through "trixie-updates". Testing and feedback would be appreciated. Bugs should be filed in the Debian Bug Tracking System, but please make the Release Team aware of them by copying "[email protected]" on your mails. The point release will also include a rebuild of debian-installer. Miscellaneous Bugfixes ---------------------- This stable update adds a few important corrections to the following packages: Package Reason ------- ------ akonadi-search Fix crash with empty input alsa-lib Fix heap overflow issue [CVE-2026-25068] ansible-core New upstream stable release; fix arbitrary code injection issue [CVE-2026-11332] at-spi2-core Fix atkversion.h header for C++ linkage audit Add support for the riscv64 architecture auto-apt-proxy Prevent apt-helper call from recursing into auto-apt-proxy; wait for network to be online awffull Fix visit / page statistics base-files Update for the point release; add AGPL-3.0, Artistic-2.0, BSL-1.0, CC-BY-3.0, CC-BY-4.0, CC-BY-SA-3.0, CC-BY-SA-4.0, GFDL-1.1 and OFL-1.1 to common-licenses bash Rebuild with updated glibc bcg729 Fix division by zero bettercap Fix mysql.server module remote DoS via crafted client handshake [CVE-2026-8276]; stop installing systemd service by default bglibs Rebuild with updated glibc binwalk Fix path traversal issue [CVE-2026-7179] busybox Rebuild with updated glibc catatonit Rebuild with updated glibc cdebootstrap Rebuild with updated glibc chkrootkit Rebuild with updated glibc cinnamon Fix download and update of spices (applets, desklets, extensions and themes) condor Rebuild with updated glibc curl Fix OpenSSL engine loading return value; remove trailing whitespaces causing test failures cyrus-imapd Allow JMAP EventSource without WebSocket/wslay; fix insufficient access check issues [CVE-2026-47084 CVE-2026-47086 CVE-2026-47087 CVE-2026-47081 CVE-2026-47089 CVE-2026-47085 CVE-2026-47083 CVE-2026-47082]; fix out of bounds read issue [CVE-2026-47088] dar Rebuild with updated glibc; rebuild with updated curl; fix glibc Built-Using regression dcmtk Fix denial of service issues [CVE-2026-35505 CVE-2026-44628 CVE-2026-50254]; fix path traversal issues [CVE-2026-50003 CVE-2026-52868] debian-edu-install Skip Icinga 2 IDO MySQL dbconfig setup dhcpcd Fix IPv6 Neighbor Discovery option parsing to discard advertisements with zero-length options [CVE-2026-14258] dnsmasq Fix buffer overflow issue [CVE-2026-12725]; fix out of bounds read issue [CVE-2026-12969] docker.io Rebuild with updated glibc flask Ensure Vary: Cookie is set on session access [CVE-2026-27205] fluidsynth Fix buffer overflow issues [CVE-2026-58264 CVE-2026-61714] glib2.0 Fix out of bounds access issues [CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014]; fix file content disclosure issue [CVE-2026-58015]; fix denial of service issue [CVE-2026-15588]; fix integer underflow issue [CVE-2026-58016]; fix out of bounds write issue [CVE-2026-16118] glibc Fix buffer overflow/underflow issues [CVE-2026-5928 CVE-2026-5450]; compatibility with linux 7.0 headers gnupg2 Rebuild with updated glibc goaccess Fix out of bounds write issue [CVE-2026-54715]; fix denial of service issue [CVE-2026-55768 CVE-2026-55777] gpsd Fix gpsprof command and code injection in gnuplot script generation [CVE-2026-58459 CVE-2026-60122] gzip Fix insecure temporary file handling issue [CVE-2026-41991]; fix buffer overflow issue [CVE-2026-41992] imagemagick Fix buffer overflow isses [CVE-2026-56362 CVE-2026-56372 CVE-2026-56374 CVE-2026-61464]; fix memory leak issues [CVE-2026-56366 CVE-2026-56375 CVE-2026-61863 CVE-2026-61864 CVE-2026-61865 CVE-2026-61866 CVE-2026-61867 CVE-2026-61868 CVE-2026-61869 CVE-2026-61870 CVE-2026-61871 CVE-2026-61872]; fix use-after- free issues [CVE-2026-56373 CVE-2026-61857 CVE-2026-61860 CVE-2026-61861]; fix denial of service issue [CVE-2026-61465]; fix policy bypass issues [CVE-2026-61858 CVE-2026-61859]; fix information disclosure issue [CVE-2026-61862] incus Fix path traversal issue [CVE-2026-81500]; fix insufficent access check issue [CVE-2026-81501] integrit Rebuild with updated glibc libcap2 Rebuild with updated glibc libdatetime-timezone-perl Update to Olson 2026c; Alberta, CA permanently -06; Morocco, permanently 00 libdbd-csv-perl Fix test failure libhttp-tiny-perl Fix CRLF validation issue [CVE-2026-7010]; fix credential forwarding on redirects issue [CVE-2026-7017] libio-compress-perl Fix header parsing issue [CVE-2025-15649]; fix denial of service issue [CVE-2026-48959]; fix crash in zipdetails [CVE-2026-48961]; fix code execution issue [CVE-2026-48962] libmodule-cpants-analyse- Backport fix for interoperability with perl Archive::Tar >= 3.08 libmongocrypt Fix missing input validation issue [CVE-2026-81523] libnet-cidr-set-perl Fix IPv4/IPv6 CIDR parsing validation [CVE-2026-49940 CVE-2026-49941 CVE-2026-49942] libnfs Fix integer overflow [CVE-2026-53689] libraw Fix out of bounds read issue [CVE-2026-5342]; fix integer overflow issues [CVE-2026-20884 CVE-2026-24450]; fix buffer overflow issues [CVE-2026-20889 CVE-2026-21413 CVE-2026-24660] libsdl2-image Fix out of bounds read issue [CVE-2026-35444]; improve parser robustness libsdl3-image Fix out of bounds read issue [CVE-2026-35444]; improve parser robustness libsocket-perl Fix out of bounds read issue [CVE-2026-12087] libssh2 Fix buffer overflow issues [CVE-2026-58050 CVE-2026-66035 CVE-2026-58051]; fix double free issue [CVE-2026-66032]; fix integer underflow issue [CVE-2026-66033]; fix data leak issue [CVE-2026-66034] libvirt Fix buffer overflow issue [CVE-2026-18917]; fix record injection issue [CVE-2026-61477]; fix denial of service issue [CVE-2026-61478]; fix privilege escalation issue [CVE-2026-63622]; fix information disclosure issue [CVE-2026-63623] libwebsockets Fix denial of service issue [CVE-2026-10650]; fix out of bounds write issue [CVE-2026-78161] llvm-toolchain-22 New package to support chromium builds lua-geoip Fix failure to build after geoip downgrade lwip Fix SNMPv3 authentication buffer overflow [CVE-2026-8836] lxc Rebuild with updated glibc; fix memory leak issue; fix running nested containers using current versions of runc mariadb New upstream stable release; fix code execution issues [CVE-2026-44168 CVE-2026-48163 CVE-2026-48165]; fix authorization bypass [CVE-2026-44169]; fix path traversal issue [CVE-2026-44171]; fix SQL injection issue [CVE-2026-44172]; fix incomplete privilege check issue [CVE-2026-44173]; fix "Illegal mix of collations" error; fix "Mroonga hangs on invalid index flag"; fix crash in information_schema.table_constraints mbedtls Fix signature algorithm injection issue [CVE-2026-25834]; fix PSA random generator cloning issue [CVE-2026-25835]; fix improper validation issue [CVE-2026-34872]; fix client impersonation issue [CVE-2026-34873]; fix NULL pointer dereference issue [CVE-2026-34874]; fix buffer overflow issue [CVE-2026-34875]; fix validation bypass issue [CVE-2026-34876] milib Handle uncaught exceptions mongo-c-driver Fix missing input validation issue [CVE-2026-81524] mrtg Fix privilege escalation issue [CVE-2026-72694] node-lodash Fix prototype pollution issues [CVE-2025-13465 CVE-2025-13465]; validate imports keys in _.template [CVE-2026-4800] onionshare Prevent writing files in Receive mode when file uploads are disabled [CVE-2026-54707]; prevent empty folder from being created when no file is uploaded [CVE-2026-54706] opencryptoki Fix privilege escalation issue [CVE-2026-23893]; fix out of bounds read issue [CVE-2026-40253] openssl New upstream release openvpn-dco-dkms Fix use-after-free in peer teardown org-roam Add missing dependency on elpa-emacsql-sqlite patool Fix path traversal vulnerability [CVE-2026-29509] pcre2 Fix several out of bounds access issues perl Fix credential forwarding on redirects issue [CVE-2026-7017]; fix symlink extraction issue [CVE-2026-42496]; fix hardlink extraction issue [CVE-2026-42497]; fix out of bounds read issues [CVE-2026-12087 CVE-2026-57432]; fix incorrect regular expression match issue [CVE-2026-13221]; fix header parsing issue [CVE-2025-15649]; fix CRLF validation issue [CVE-2026-7010]; fix buffer overflow issue [CVE-2026-8376]; fix denial of service issue [CVE-2026-48959]; fix crash in zipdetails [CVE-2026-48961]; fix code execution issue [CVE-2026-48962]; fix signed integer overflow issue [CVE-2026-57433] php-guzzlehttp-psr7 Fix CRLF injection in HTTP start-line parsing [CVE-2026-55766] proftpd-dfsg Fix SQL injection issue [CVE-2026-44331]; fix buffer overflow issues [CVE-2026-53994 CVE-2026-63090]; fix integer overflow issue [CVE-2026-63091] pyasn1 Fix denial of service issues [CVE-2026-59884 CVE-2026-59885 CVE-2026-59886] python-ecdsa Prevent exceptions when handling truncated DER [CVE-2026-33936] python3.13 Fix use-after-free in dict.clear() with embedded values, resolving regression from previous version; fix injection issue [CVE-2026-0864]; fix file overwrite issue [CVE-2026-11940]; fix denial of service issues [CVE-2026-11972 CVE-2026-6879]; fix incorrect handling of user / group IDs in tar files [CVE-2026-4360] qemu New upstream stable release; fix integer overflow issue [CVE-2026-15264]; fix secure boot bypass [CVE-2026-16288]; fix infinite loop [CVE-2026-16457]; fix buffer overflow issues [CVE-2026-17516 CVE-2026-50626 CVE-2026-58581 CVE-2026-58582 CVE-2026-63110; virtio-gpu: reject requests with short/truncated control headers [CVE-2026-18054]; fix use-after-free issues [CVE-2026-50624 CVE-2026-63322 CVE-2026-63323]; fix out of bounds write issue [CVE-2026-61402]; hw/uefi: add post_load checks [CVE-2026-61404]; fix denial of service issues [CVE-2026-61405 CVE-2026-61406]; fix memory leak issue [CVE-2026-61476]; fix out of bounds read issues [CVE-2026-63109 CVE-2026-63320 CVE-2026-65928 CVE-2026-65929 CVE-2026-66021]; fix 9pfs Readonly O_TRUNC/O_APPEND Bypass issue [CVE-2026-63318]; virtio: use masked features with set_features_ex [CVE-2026-63321]; virtio- net: qemu_bh_new_guarded uses wrong DeviceState, bypassing MMIO reentrancy protection [CVE-2026-66022] refpolicy Enable usbguard SELinux policy and fix its confinement; fix SELinux policy for PAM login records, chromium clipboard, pulseaudio, systemd-nspawn/passwd-agent, dhcpc/ntp, and sympa file labelling rsyslog Fix denial of service issue [CVE-2026-19654]; omfwd regression fix: avoid false active target change log message; fix buffer overflow issues [CVE-2026-78002 CVE-2026-61548] rust-cbindgen-web New package to support browser builds rustc Fix documentation merging and fix build on 32-bit ARM platforms; fix tar header processing and an unpack vulnerability [CVE-2026-33055 CVE-2026-33056]; fix cargo credential leakage and cache poisoning [CVE-2026-5222 CVE-2026-5223] rustc-web New package to support browser builds samba New upstream stable release sash Rebuild with updated glibc sbsigntool Fix intermediate certificate verification sg3-utils Fix missing sg_inq output fields snapd Rebuild with updated glibc socat Fix buffer overflow issue [CVE-2026-56123] spip Security fixes sqlite3 Fix FTS5 handling of corrupt records [CVE-2026-11822 CVE-2026-11824] squid Fix out of bounds read issue [CVE-2026-33515] tini Rebuild with updated glibc transmission Fix clickjacking issue [CVE-2026-38978] tripwire Rebuild with updated glibc tsocks Rebuild with updated glibc tzdata New upstream stable release; update timezone data for Alberta and Morocco; update leap second data u-boot Fix BOOTP/DHCP buffer overread [CVE-2024-42040]; fix FIT signature verification bypass [CVE-2026-46728] unixodbc Fix memory leaks on dlclose() user-mode-linux Rebuild with updated linux wolfssl Fix digest, MAC, and AES-GCM validation [CVE-2026-5194 CVE-2026-6329 CVE-2026-6331 CVE-2026-55967]; fix PKCS7 bounds, overflow, and certificate handling [CVE-2026-6094 CVE-2026-6678 CVE-2026-6681 CVE-2026-7511]; ensure certificate validation [CVE-2026-55960 CVE-2026-55961 CVE-2026-6450 CVE-2026-6731]; fix TLS handshake state and algorithms [CVE-2026-55962 CVE-2026-6092 CVE-2026-6325] xapian-core Fix missing escaping xfsprogs Avoid unnecessary "permission denied" logging in other services zsh Rebuild with updated glibc A complete list of all accepted and rejected packages together with rationale is on the preparation page for this revision: <https://release.debian.org/proposed-updates/stable.html> If you encounter any issues, please don't hesitate to get in touch with the Debian Release Team at "[email protected]".
signature.asc
Description: This is a digitally signed message part
