Source: mina2 Version: 2.2.1-4 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for mina2. CVE-2026-47065[0]: | ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter | Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. | When the serialised stream contains a TC_PROXYCLASSDESC (the marker | for a java.lang.reflect.Proxy ), JDK’s | ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the | default ObjectInputStream.resolveProxyClass(interfaces) | implementation, which performs Class.forName(intf, false, | latestUserDefinedLoader()) for EACH interface name and constructs | the proxy class — bypassing the accepted classes list . | ZDRES-233: Class.forName(name, initialize=true, classLoader) in | readClassDescriptor Triggers Static Initialiser of Allow-Listed | Classes Assessment: Fully addressed. For ANY class on the allow- | list, deserialising a stream that names it triggers the class’s | (static initialiser) BEFORE any instance is constructed. This means | an attacker who supplies a class name on the allow-list (e.g., the | developer wrote accept(“com.myapp.*") , attacker supplies | com.myapp.SomeClass ) causes <clinit> of SomeClass — and many | real-world classes have side-effecting static initialisers Both | issues have been fixed. CVE-2026-47321[1]: | Unbounded Decompression Amplification DoS in Apache Mina Zlib.inflate If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-47065 https://www.cve.org/CVERecord?id=CVE-2026-47065 [1] https://security-tracker.debian.org/tracker/CVE-2026-47321 https://www.cve.org/CVERecord?id=CVE-2026-47321 [2] https://lists.apache.org/thread/y7xj1bl8qo47p9bktb11hg5v6k1d4dyj Please adjust the affected versions in the BTS as needed. Regards, Salvatore __ This is the maintainer address of Debian's Java team <https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-java-maintainers>. Please use [email protected] for discussions and questions.
