Vulnerabilities

531 via 2109 paths

Dependencies

413

Source

Group 6 Copy Created with Sketch. Docker

Target OS

debian:12
Test your Docker Hub image against our market leading vulnerability database Sign up for free
Severity
  • 4
  • 28
  • 17
  • 482
Status
  • 531
  • 0
  • 0

critical severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, readVariableLengthInteger() decodes a variable-length integer from untrusted EXR input without bounding the shift count. After enough continuation bytes, the code executes a left shift by 70 on a 64-bit value, which is undefined behavior. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

Remediation

There is no fixed version for Debian:12 openexr.

References

critical severity

Integer Overflow or Wraparound

  • Vulnerable module: zlib/zlib1g
  • Introduced through: zlib/zlib1g@1:1.2.13.dfsg-1 and zlib/zlib1g-dev@1:1.2.13.dfsg-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › zlib/zlib1g@1:1.2.13.dfsg-1
  • Introduced through: buildpack-deps@bookworm › zlib/zlib1g-dev@1:1.2.13.dfsg-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream zlib package and not the zlib package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field. NOTE: MiniZip is not a supported part of the zlib product. NOTE: pyminizip through 0.2.6 is also vulnerable because it bundles an affected zlib version, and exposes the applicable MiniZip code through its compress API.

Remediation

There is no fixed version for Debian:12 zlib.

References

critical severity

Out-of-bounds Read

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, IDManifest::init() reconstructs strings from a prefix-compressed representation. If the previous string is longer than 255 bytes, the next string is expected to begin with a 2-byte prefix length. The code reads stringList[i][0] and stringList[i][1] without checking that the current string has at least two bytes. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

Remediation

There is no fixed version for Debian:12 openexr.

References

critical severity

CVE-2026-13221

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.10 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk.

When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error.

A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.

Remediation

There is no fixed version for Debian:12 perl.

References

high severity
new

Release of Invalid Pointer or Reference

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.

Remediation

There is no fixed version for Debian:12 libxml2.

References

high severity

CVE-2026-57432

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack.

S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds.

A template derived from untrusted input can read heap memory past the buffer and return it to the caller.

Remediation

There is no fixed version for Debian:12 perl.

References

high severity

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a crafted HEIF sequence file where the saiz box declares more samples than actually exist in the track's chunk table causes a heap-buffer-overflow (out-of-bounds read) in the SampleAuxInfoReader constructor. The SampleAuxInfoReader constructor iterates over saiz->get_num_samples() samples but doesn't validate that this count is consistent with the number of chunks in the chunks vector. When saiz declares more samples than the chunks cover, the loop increments current_chunk past chunks.size(), causing an out-of-bounds read on the chunks vector. The vulnerability is triggered during file parsing (heif_context_read_from_file) without any additional user interaction. Any application using libheif to open untrusted HEIF files is affected. This issue has been fixed in version 1.22.0.

Remediation

There is no fixed version for Debian:12 libheif.

References

high severity
new

Missing Release of File Descriptor or Handle after Effective Lifetime

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The nsenter --join-cgroup option opens the target cgroup.procs file as root and leaves that file descriptor open across later namespace and credential changes and across execve(). Because the kernel checks later cgroup migrations using the credentials from the original open, a program run in an attacker-controlled target can inherit root's ability to move host processes between cgroups. After a privileged operator uses --join-cgroup against that target, an unprivileged user can migrate and terminate unrelated root processes.

Remediation

There is no fixed version for Debian:12 util-linux.

References

high severity

Out-of-bounds Write

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.19.0 through 1.21.2, a crafted HEIF file (uncompressed unci codec, tiled, component-interleaved, 4:2:0) triggers a heap out-of-bounds write in libheif's uncompressed tile decoder. The write overwrites the C++ vtable pointer of an adjacent unc_decoder_component_interleave object; the next virtual call dispatches to an attacker-chosen address. Version 1.22.0 patches the issue.

Remediation

There is no fixed version for Debian:12 libheif.

References

high severity
new

Use After Free

  • Vulnerable module: librsvg/gir1.2-rsvg-2.0
  • Introduced through: librsvg/gir1.2-rsvg-2.0@2.54.7+dfsg-1~deb12u1, librsvg/librsvg2-2@2.54.7+dfsg-1~deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › librsvg/gir1.2-rsvg-2.0@2.54.7+dfsg-1~deb12u1
  • Introduced through: buildpack-deps@bookworm › librsvg/librsvg2-2@2.54.7+dfsg-1~deb12u1
  • Introduced through: buildpack-deps@bookworm › librsvg/librsvg2-common@2.54.7+dfsg-1~deb12u1
  • Introduced through: buildpack-deps@bookworm › librsvg/librsvg2-dev@2.54.7+dfsg-1~deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream librsvg package and not the librsvg package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free error can occur. This vulnerability arises because the library incorrectly frees an XML entity that is still in use by the parser. An attacker could potentially exploit this to cause a denial of service or execute arbitrary code.

Remediation

There is no fixed version for Debian:12 librsvg.

References

high severity
new

Heap-based Buffer Overflow

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.

Remediation

There is no fixed version for Debian:12 libxml2.

References

high severity
new

Incorrect Resource Transfer Between Spheres

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevance for, for example, the XML_PARSE_NONET flag, if (without it) a custom resource loader accesses the internet and triggers XML external entity injection, SSRF, or a denial of service (e.g., for an attacker-controlled internet resource that is intentionally slow).

Remediation

There is no fixed version for Debian:12 libxml2.

References

high severity
new

Integer Overflow or Wraparound

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.

Remediation

There is no fixed version for Debian:12 libxml2.

References

high severity
new

Integer Overflow or Wraparound

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.

Remediation

There is no fixed version for Debian:12 libxml2.

References

high severity
new

Stack-based Buffer Overflow

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libxml2 before 2.15.4, xmlSnprintfElements in valid.c has a strcat stack-based buffer overflow.

Remediation

There is no fixed version for Debian:12 libxml2.

References

high severity

Out-of-bounds Read

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.1.0 to before 3.2.7, 3.3.9, and 3.4.9, internal_exr_undo_piz() advances the working wavelet pointer with signed 32-bit arithmetic. Because nx, ny, and wcount are int, a crafted EXR file can make this product overflow and wrap. The next channel then decodes from an incorrect address. The wavelet decode path operates in place, so this yields both out-of-bounds reads and out-of-bounds writes. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

Remediation

There is no fixed version for Debian:12 openexr.

References

high severity

Out-of-bounds Write

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In CompositeDeepScanLine::readPixels, per-pixel totals are accumulated in vector<unsigned int> total_sizes for attacker-controlled large counts across many parts, total_sizes[ptr] wraps modulo 2^32. overall_sample_count is then derived from wrapped totals and used in samples[channel].resize(overall_sample_count). Decode pointer setup/consumption proceeds with true sample counts, and write operations in core unpack (generic_unpack_deep_pointers) overrun the undersized composite sample buffer. This vulnerability is fixed in v3.2.6, v3.3.8, and v3.4.6.

Remediation

There is no fixed version for Debian:12 openexr.

References

high severity
new

Detection of Error Condition Without Action

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

util-linux versions through 2.41.5 and 2.42.2 fail to check mount helper exit status before running post-mount hooks, allowing unprivileged users to execute privileged operations on pre-existing filesystems. Attackers can exploit X-mount.idmap or X-mount.owner hooks to clone filesystems with inherited suid bits or modify target inode permissions after a helper fails, achieving privilege escalation.

Remediation

There is no fixed version for Debian:12 util-linux.

References

high severity
new

Time-of-check Time-of-use (TOCTOU)

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in util-linux. Restricted bind mounts take the source path from fstab but do not pin that source before the privileged mount. A local unprivileged user who can replace the authorized source or a writable ancestor can redirect SUID mount(8) to bind another host directory. If the fstab entry also sets X-mount.owner, X-mount.group, or X-mount.mode, root then changes ownership or mode on that redirected inode.

Remediation

There is no fixed version for Debian:12 util-linux.

References

high severity
new

Improper Handling of Unicode Encoding

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malformed UTF-16 sequences to be accepted. Attackers can supply UTF-16 encoded XML containing lone high surrogates that consume the following code unit, causing Expat to pass unpaired surrogates to applications built with XML_UNICODE and to silently replace input characters in other builds.

Remediation

There is no fixed version for Debian:12 expat.

References

high severity

Heap-based Buffer Overflow

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a malformed H.265 PPS NAL unit causes a segmentation fault in pic_parameter_set::set_derived_values(). This issue has been patched in version 1.0.17.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

high severity

Use of Uninitialized Resource

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, sensitive information from heap memory may be leaked through the decoded pixel data (information disclosure). This occurs under default settings; simply reading a malicious EXR file is sufficient to trigger the issue, without any user interaction. This issue has been patched in version 3.4.8.

Remediation

There is no fixed version for Debian:12 openexr.

References

high severity

CVE-2026-15308

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.

Remediation

There is no fixed version for Debian:12 python3.11.

References

high severity
new

Out-of-bounds Write

  • Vulnerable module: zlib/zlib1g
  • Introduced through: zlib/zlib1g@1:1.2.13.dfsg-1 and zlib/zlib1g-dev@1:1.2.13.dfsg-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › zlib/zlib1g@1:1.2.13.dfsg-1
  • Introduced through: buildpack-deps@bookworm › zlib/zlib1g-dev@1:1.2.13.dfsg-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream zlib package and not the zlib package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. Attackers can trigger the overflow by calling gzprintf() or gzvprintf() after a write stall, causing an unchecked memmove() to write beyond the internal input buffer boundary.

Remediation

There is no fixed version for Debian:12 zlib.

References

high severity
new

Integer Coercion Error

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for integer overflow before calling writecallback. This has security relevance for many types of uses of that length value within a callback.

Remediation

There is no fixed version for Debian:12 libxml2.

References

high severity

Heap-based Buffer Overflow

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.7, an attacker providing a crafted .exr file with HTJ2K compression and a channel width of 32768 can write controlled data beyond the output heap buffer in any application that decodes EXR images. The write primitive is 2 bytes per overflow iteration or 4 bytes (by another path), repeating for each additional pixel past the overflow point. In this context, a heap write overflow can lead to remote code execution on systems. This issue has been patched in version 3.4.7.

Remediation

There is no fixed version for Debian:12 openexr.

References

high severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From version 3.4.0 to before version 3.4.8, a crafted B44 or B44A EXR file can cause an out-of-bounds write in any application that decodes it via exr_decoding_run(). Consequences range from immediate crash (most likely) to corruption of adjacent heap allocations (layout-dependent). This issue has been patched in version 3.4.8.

Remediation

There is no fixed version for Debian:12 openexr.

References

high severity

Heap-based Buffer Overflow

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATAFMT_8BITABGR output format and a specific stride value, leading to a heap-based buffer overflow. This could potentially result in arbitrary code execution or a denial of service (DoS).

Remediation

There is no fixed version for Debian:12 tiff.

References

high severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, internal_dwa_compressor.h:1722 performs curc-&gt;width * curc-&gt;height in int32 arithmetic without a (size_t) cast. This is the same overflow pattern fixed in other locations by the recent CVE-2026-34589 batch, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses internal_dwa_compressor.h:1722.

Remediation

There is no fixed version for Debian:12 openexr.

References

high severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.4.0 through 3.4.9, 3.3.0 through 3.3.9, and 3.2.0 through 3.2.7, internal_dwa_compressor.h:1040 performs chan-&gt;width * chan-&gt;bytes_per_element in int32 arithmetic without a (size_t) cast. This is the same overflow pattern fixed in other decoders by CVE-2026-34589/34588/34544, but this line was missed. Versions 3.4.10, 3.3.10, and 3.2.8 contain a fix that addresses internal_dwa_compressor.h:1040.

Remediation

There is no fixed version for Debian:12 openexr.

References

high severity
new

Expired Pointer Dereference

  • Vulnerable module: gcc-12
  • Introduced through: gcc-12@12.2.0-14+deb12u1, gcc-12/cpp-12@12.2.0-14+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gcc-12@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/cpp-12@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/g++-12@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/gcc-12-base@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libasan8@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libatomic1@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libcc1-0@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libgcc-12-dev@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libgcc-s1@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libgomp1@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libitm1@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/liblsan0@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libquadmath0@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libstdc++-12-dev@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libstdc++6@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libtsan2@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libubsan1@12.2.0-14+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream gcc-12 package and not the gcc-12 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, the library reallocates storage but fails to update its internal entry pointer. An attacker capable of triggering this operation can exploit this use-after-free condition, leading to a Denial of Service (DoS) via an application crash or potential memory corruption.

Remediation

There is no fixed version for Debian:12 gcc-12.

References

high severity
new

Link Following

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The X-mount.subdir option uses a detached-tree fast path on Linux 6.15 and later and passes the configured subdirectory to open_tree() with AT_SYMLINK_NOFOLLOW. That flag does not stop intermediate symlink traversal or keep resolution inside the newly mounted filesystem. A local unprivileged user with an fstab-authorized X-mount.subdir entry can attach a host path at the intended mountpoint.

Remediation

There is no fixed version for Debian:12 util-linux.

References

medium severity
new

CVE-2026-60585

  • Vulnerable module: mariadb/libmariadb-dev
  • Introduced through: mariadb/libmariadb-dev@1:10.11.18-0+deb12u1, mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb3@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/mariadb-common@1:10.11.18-0+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream mariadb package and not the mariadb package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

Remediation

There is no fixed version for Debian:12 mariadb.

References

medium severity

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer underflow in the Chunk constructor (m_last_sample = 0 + 0 - 1 = UINT32_MAX), mapping all samples to an empty chunk and resulting in a denial of service. When any sample is accessed, the library reads from index 0 of an empty std::vector, causing a guaranteed SEGV (null-page read). The file parses successfully without producing an error; the crash occurs on the first frame access. This issue has been fixed in version 1.22.0.

Remediation

There is no fixed version for Debian:12 libheif.

References

medium severity
new

CVE-2026-60331

  • Vulnerable module: mariadb/libmariadb-dev
  • Introduced through: mariadb/libmariadb-dev@1:10.11.18-0+deb12u1, mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb3@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/mariadb-common@1:10.11.18-0+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream mariadb package and not the mariadb package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in takeover of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.4 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

Remediation

There is no fixed version for Debian:12 mariadb.

References

medium severity
new

CVE-2026-60747

  • Vulnerable module: mariadb/libmariadb-dev
  • Introduced through: mariadb/libmariadb-dev@1:10.11.18-0+deb12u1, mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb3@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/mariadb-common@1:10.11.18-0+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream mariadb package and not the mariadb package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server, MySQL Cluster executes to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 6.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).

Remediation

There is no fixed version for Debian:12 mariadb.

References

medium severity
new

Out-of-bounds Read

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-bounds read, aka an out-of-bounds read in the NXT macro in xmlregexp.

Remediation

There is no fixed version for Debian:12 libxml2.

References

medium severity
new

Heap-based Buffer Overflow

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the tiff2pdf utility due to an integer truncation error when processing crafted BigTIFF files. An attacker can provide a specially crafted BigTIFF file, causing a 64-bit StripByteCounts value to be truncated to a 32-bit integer. This leads to an undersized memory allocation and a subsequent out-of-bounds memory copy, resulting in a crash and severe memory corruption.

Remediation

There is no fixed version for Debian:12 tiff.

References

medium severity
new

Integer Overflow or Wraparound

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libexpat versions 2.7.2 through 2.8.5 contain an integer overflow vulnerability in expat_realloc() function on 32-bit platforms when computing allocation sizes. Attackers supplying malicious XML to applications parsing with vulnerable libexpat can cause heap buffer overflow, memory corruption, or denial of service.

Remediation

There is no fixed version for Debian:12 expat.

References

medium severity
new

Inefficient Regular Expression Complexity

  • Vulnerable module: dash
  • Introduced through: dash@0.5.12-2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › dash@0.5.12-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream dash package and not the dash package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recursion over candidate positions. A local user who can plant filenames, or otherwise feed that matcher, can make a short multi-star pattern such as ....*.tar.gz consume excessive CPU.

Remediation

There is no fixed version for Debian:12 dash.

References

medium severity

NULL Pointer Dereference

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Versions prior to 1.22.0 crashes in the public C API heif_image_handle_get_image_tiling() when a malformed uncompressed HEIF image item has an associated uncC property but no associated ispe property. In debug builds this trips the ispe &amp;&amp; uncC assertion in ImageItem_uncompressed::get_heif_image_tiling(). In a release/NDEBUG ASan build, the same file causes a null pointer read at address 0xa8. Version 1.22.0 fixes the issue.

Remediation

There is no fixed version for Debian:12 libheif.

References

medium severity
new

NULL Pointer Dereference

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in libxml2. A local user or an attacker providing a specially crafted XML catalog can trigger a NULL pointer dereference during XML catalog parsing. This occurs when a nextCatalog element lacks its mandatory catalog attribute, leading to the application crashing and causing a Denial of Service (DoS).

Remediation

There is no fixed version for Debian:12 libxml2.

References

medium severity

CVE-2025-12781

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the characters "+/" will always be accepted, regardless of the value of "altchars" parameter, typically used to establish an "alternative base64 alphabet" such as the URL safe alphabet. This behavior matches what is recommended in earlier base64 RFCs, but newer RFCs now recommend either dropping characters outside the specified base64 alphabet or raising an error. The old behavior has the possibility of causing data integrity issues.

This behavior can only be insecure if your application uses an alternate base64 alphabet (without "+/"). If your application does not use the "altchars" parameter or the urlsafe_b64decode() function, then your application does not use an alternative base64 alphabet.

The attached patches DOES NOT make the base64-decode behavior raise an error, as this would be a change in behavior and break existing programs. Instead, the patch deprecates the behavior which will be replaced with the newly recommended behavior in a future version of Python. Users are recommended to mitigate by verifying user-controlled inputs match the base64 alphabet they are expecting or verify that their application would not be affected if the b64decode() functions accepted "+" or "/" outside of altchars.

Remediation

There is no fixed version for Debian:12 python3.11.

References

medium severity

Authentication Bypass

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in util-linux. Improper hostname canonicalization in the login(1) utility, when invoked with the -h option, can modify the supplied remote hostname before setting PAM_RHOST. A remote attacker could exploit this by providing a specially crafted hostname, potentially bypassing host-based Pluggable Authentication Modules (PAM) access control rules that rely on fully qualified domain names. This could lead to unauthorized access.

Remediation

There is no fixed version for Debian:12 util-linux.

References

medium severity

Use After Free

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in a dynamically allocated array. When subsequent partition additions cause the array to be reallocated, this pointer becomes stale, leading to a heap use-after-free read. An attacker who can present a crafted block device image (for example, via USB insertion or a loop-mounted disk image) can trigger this flaw without user interaction, as libblkid is invoked automatically by udev/udisks as root on block-device hot-plug events. This could lead to limited information disclosure or denial of service.

Remediation

There is no fixed version for Debian:12 util-linux.

References

medium severity

Out-of-bounds Write

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.17, a crafted HEVC bitstream causes an out-of-bounds heap write confirmed by AddressSanitizer. The trigger is a stale ctb_info.log2unitSize after an SPS change where PicWidthInCtbsY and PicHeightInCtbsY stay constant but Log2CtbSizeY changes, causing set_SliceHeaderIndex to index past the allocated image metadata array and write 2 bytes past the end of a heap allocation. This issue has been patched in version 1.0.17.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

medium severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, the DWA lossy decoder constructs temporary per-component block pointers using signed 32-bit arithmetic. For a large enough width, the calculation overflows and later decoder stores operate on a wrapped pointer outside the allocated rowBlock backing store. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

Remediation

There is no fixed version for Debian:12 openexr.

References

medium severity
new

CVE-2026-47023

  • Vulnerable module: mariadb/libmariadb-dev
  • Introduced through: mariadb/libmariadb-dev@1:10.11.18-0+deb12u1, mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb3@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/mariadb-common@1:10.11.18-0+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream mariadb package and not the mariadb package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

Remediation

There is no fixed version for Debian:12 mariadb.

References

medium severity
new

CVE-2026-60184

  • Vulnerable module: mariadb/libmariadb-dev
  • Introduced through: mariadb/libmariadb-dev@1:10.11.18-0+deb12u1, mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb3@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/mariadb-common@1:10.11.18-0+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream mariadb package and not the mariadb package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, MySQL Cluster. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

Remediation

There is no fixed version for Debian:12 mariadb.

References

low severity

Out-of-bounds Write

  • Vulnerable module: aom/libaom3
  • Introduced through: aom/libaom3@3.6.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › aom/libaom3@3.6.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream aom package and not the aom package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().

Remediation

There is no fixed version for Debian:12 aom.

References

low severity

Out-of-Bounds

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass stack guard protection. The component is: nptl. The attack vector is: Exploit stack buffer overflow vulnerability and use this bypass vulnerability to bypass stack guard. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

OS Command Injection

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

CVE-2026-8376

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5.43.0 before 5.43.11 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds.

Perl_study_chunk in regcomp_study.c checked the size of the joined substring buffer in characters rather than bytes. For a quantified fixed substring with a large minimum count, the byte length mincount * l could overflow SSize_t, producing an undersized SvGROW allocation; the subsequent copy writes past the end of the buffer.

A caller that compiles an attacker-controlled regular expression on a 32-bit perl build triggers a heap buffer overflow at compile time.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2005-2541

  • Vulnerable module: tar
  • Introduced through: tar@1.34+dfsg-1.2+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tar@1.34+dfsg-1.2+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream tar package and not the tar package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Tar 1.15.1 does not properly warn the user when extracting setuid or setgid files, which may allow local users or remote attackers to gain privileges.

Remediation

There is no fixed version for Debian:12 tar.

References

low severity

Integer Underflow

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a node element nested within other elements like method, signal, property or arg. This issue can cause an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Out-of-bounds Write

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Due to a failure in validating the number of scanline samples of a OpenEXR file containing deep scanline data, Academy Software Foundation OpenEX image parsing library version 3.2.1 and prior is susceptible to a heap-based buffer overflow vulnerability. This issue was resolved as of versions v3.2.2 and v3.1.12 of the affected library.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

CVE-2026-42496

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.

_make_special_file() passes the tar header's linkname to symlink() without validating it against absolute paths or .. segments. The secure-extract mode check that guards regular file extraction does not cover the symlink target.

A subsequent open through the extracted name reads or writes the attacker chosen path.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2025-7458

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attacker with the ability to execute arbitrary SQL statements to cause a denial of service or disclose sensitive information from process memory via a crafted SELECT statement with a large number of expressions in the ORDER BY clause.

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

Improper Encoding or Escaping of Output

  • Vulnerable module: git
  • Introduced through: git@1:2.39.5-0+deb12u3 and git/git-man@1:2.39.5-0+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › git@1:2.39.5-0+deb12u3
  • Introduced through: buildpack-deps@bookworm › git/git-man@1:2.39.5-0+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream git package and not the git package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Git is a source code management tool. When cloning from a server (or fetching, or pushing), informational or error messages are transported from the remote Git process to the client via the so-called "sideband channel". These messages will be prefixed with "remote:" and printed directly to the standard error output. Typically, this standard error output is connected to a terminal that understands ANSI escape sequences, which Git did not protect against. Most modern terminals support control sequences that can be used by a malicious actor to hide and misrepresent information, or to mislead the user into executing untrusted scripts. As requested on the git-security mailing list, the patches are under discussion on the public mailing list. Users are advised to update as soon as possible. Users unable to upgrade should avoid recursive clones unless they are from trusted sources.

Remediation

There is no fixed version for Debian:12 git.

References

low severity

CVE-2019-1010023

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Libc current is affected by: Re-mapping current loaded library with malicious ELF file. The impact is: In worst case attacker may evaluate privileges. The component is: libld. The attack vector is: Attacker sends 2 ELF files to victim and asks to run ldd on it. ldd execute code. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2023-49463

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif v1.17.5 was discovered to contain a segmentation violation via the function find_exif_tag at /libheif/exif.cc.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Out-of-Bounds

  • Vulnerable module: libwmf/libwmf-0.2-7
  • Introduced through: libwmf/libwmf-0.2-7@0.2.12-5.1, libwmf/libwmf-dev@0.2.12-5.1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libwmf/libwmf-0.2-7@0.2.12-5.1
  • Introduced through: buildpack-deps@bookworm › libwmf/libwmf-dev@0.2.12-5.1
  • Introduced through: buildpack-deps@bookworm › libwmf/libwmflite-0.2-7@0.2.12-5.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libwmf package and not the libwmf package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.

Remediation

There is no fixed version for Debian:12 libwmf.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An integer overflow vulnerability was found in tiftoimage function in openjpeg 2.1.2, resulting in heap buffer overflow.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Out-of-Bounds

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An infinite loop vulnerability in tiftoimage that results in heap buffer overflow in convert_32s_C1P1 was found in openjpeg 2.1.2.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Out-of-bounds Write

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in OpenJPEG 2.3.0. A heap-based buffer overflow was discovered in the function t2_encode_packet in lib/openmj2/t2.c. The vulnerability causes an out-of-bounds write, which may lead to remote denial of service or possibly unspecified other impact.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Off-by-one Error

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GLib. An off-by-one error can occur in the g_key_file_get_locale_string_list function in the gkeyfile.c file when loading a key file with an empty value. This flaw can cause an out-of-bounds access of 1 byte or a denial of service when the out-of-bounds access crosses a page boundary.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Buffer Over-read

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-serialiser.c file when doing an alignment padding check because the bounds check uses > instead of >=, causing an out-of-bounds read of only 1 byte. This issue can cause a minor information disclosure of 1 byte and a denial of service when the out-of-bounds read crosses a page boundary.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Buffer Over-read

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GLib. A buffer over-read can occur in g_io_channel_read_line_backend() in the giochannel.c file when a custom line terminator with a length greater than one is set, causing memcmp to read past the GString buffer. This vulnerability can cause a minor information disclosure of 7 bytes or a denial of service when the buffer over-read crosses a page boundary.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Buffer Over-read

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the G_REGEX_RAW compile flag and case-change replacement escapes because the string_append function processes matched substrings using UTF-8 functions that assume valid UTF-8 input, even when the string is treated as raw bytes. This vulnerability can cause a minor information disclosure of 1-5 bytes and a denial of service when the buffer over-read crosses a page boundary.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Improper Certificate Validation

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in binutils. A heap-buffer-overflow vulnerability exists when processing a specially crafted XCOFF (Extended Common Object File Format) object file during linking. A local attacker could trick a user into processing this malicious file, which could lead to arbitrary code execution, allowing the attacker to run unauthorized commands, or cause a denial of service, making the system unavailable.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as critical has been found in GNU Binutils up to 2.44. This affects the function debug_type_samep of the file /binutils/debug.c of the component objdump. The manipulation leads to memory corruption. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils up to 2.44. It has been rated as critical. Affected by this issue is the function elf_gc_sweep of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.45 is able to address this issue. It is recommended to upgrade the affected component.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability, which was classified as problematic, has been found in GNU Binutils 2.45. Affected by this issue is the function bfd_elf_set_group_contents of the file bfd/elf.c. The manipulation leads to out-of-bounds write. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The name of the patch is 41461010eb7c79fee7a9d5f6209accdaac66cc6b. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as problematic was found in GNU Binutils 2.45. Affected by this vulnerability is the function copy_section of the file binutils/objcopy.c. The manipulation leads to heap-based buffer overflow. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is named 08c3cbe5926e4d355b5cb70bbec2b1eeb40c2944. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw has been found in GNU Binutils 2.45. Impacted is the function _bfd_elf_parse_eh_frame of the file bfd/elf-eh-frame.c of the component Linker. Executing manipulation can lead to heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. This patch is called ea1a0737c7692737a644af0486b71e4a392cbca8. A patch should be applied to remediate this issue. The code maintainer replied with "[f]ixed for 2.46".

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability has been found in GNU Binutils 2.45. The affected element is the function elf_swap_shdr in the library bfd/elfcode.h of the component Linker. The manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 9ca499644a21ceb3f946d1c179c38a83be084490. To fix this issue, it is recommended to deploy a patch. The code maintainer replied with "[f]ixed for 2.46".

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Write

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An out-of-bounds write vulnerability was found in the BFD library's DLX ELF backend (bfd/elf32-dlx.c) in GNU binutils. The dlx_rtype_to_howto() function maps ELF relocation types to internal howto structures but fails to perform adequate bounds checking on attacker-controlled relocation type values (via ELF32_R_TYPE(r_info)) before indexing into the dlx_elf_howto_table[] array. The DLX relocation type number space is non-contiguous (basic types 0-6, extended types at 0x10000+), but the default case in the switch statement allows arbitrary index values to reach the array access.

A specially crafted ELF/DLX object file can trigger this out-of-bounds write when processed by any BFD-consuming tool (objdump, readelf, strip, ld, nm, objcopy). The vulnerability has been demonstrated to achieve arbitrary code execution via a File Stream Oriented Programming (FSOP) attack against glibc FILE structures (stderr), redirecting control flow to system().

Attack scenarios include CI/CD pipelines performing automated binary analysis, developer workstations running objdump/readelf on untrusted binaries, automated security scanning or malware analysis tools invoking binutils, and package build systems processing third-party code.

Note: This vulnerability is only exploitable when binutils is built with the DLX backend enabled (typically via --enable-targets=all).

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: elfutils/libelf1
  • Introduced through: elfutils/libelf1@0.188-2.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › elfutils/libelf1@0.188-2.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream elfutils package and not the elfutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability, which was classified as critical, was found in GNU elfutils 0.192. This affects the function process_symtab of the file readelf.c of the component eu-readelf. The manipulation of the argument D/a leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 5e5c0394d82c53e97750fe7b18023e6f84157b81. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 elfutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: elfutils/libelf1
  • Introduced through: elfutils/libelf1@0.188-2.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › elfutils/libelf1@0.188-2.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream elfutils package and not the elfutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the function dump_data_section/print_string_section of the file readelf.c of the component eu-readelf. The manipulation of the argument z/x leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is 73db9d2021cab9e23fd734b0a76a612d52a6f1db. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 elfutils.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libexpat before 2.7.4, the doContent function does not properly determine the buffer size bufSize because there is no integer overflow check for tag buffer reallocation.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Stack-based Buffer Overflow

  • Vulnerable module: ncurses/libncurses-dev
  • Introduced through: ncurses/libncurses-dev@6.4-4, ncurses/libncurses5-dev@6.4-4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses5-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncursesw5-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncursesw6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libtinfo6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/ncurses-base@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/ncurses-bin@6.4-4

NVD Description

Note: Versions mentioned in the description apply only to the upstream ncurses package and not the ncurses package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The infocmp command-line tool in ncurses before 6.5-20251213 has a stack-based buffer overflow in analyze_string in progs/infocmp.c.

Remediation

There is no fixed version for Debian:12 ncurses.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

Out-of-Bounds

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as critical. This vulnerability affects the function get_histogram of the file tools/tiffmedian.c. The manipulation leads to use after free. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as fe10872e53efba9cc36c66ac4ab3b41a839d5172. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Out-of-Bounds

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in LibTIFF up to 4.7.0. It has been rated as critical. This issue affects the function setrow of the file tools/thumbnail.c. The manipulation leads to buffer overflow. An attack has to be approached locally. The patch is named e8c9d6c616b19438695fd829e58ae4fde5bfbc22. It is recommended to apply a patch to fix this issue. This vulnerability only affects products that are no longer supported by the maintainer.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Out-of-Bounds

  • Vulnerable module: aom/libaom3
  • Introduced through: aom/libaom3@3.6.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › aom/libaom3@3.6.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream aom package and not the aom package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

AOMedia v3.0.0 to v3.5.0 was discovered to contain an invalid read memory access via the component assign_frame_buffer_p in av1/common/av1_common_int.h.

Remediation

There is no fixed version for Debian:12 aom.

References

low severity

CVE-2025-66864

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-66866

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in function d_abi_tags in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-69649

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Binutils thru 2.46 readelf contains a null pointer dereference vulnerability when processing a crafted ELF binary with malformed header fields. During relocation processing, an invalid or null section pointer may be passed into display_relocations(), resulting in a segmentation fault (SIGSEGV) and abrupt termination. No evidence of memory corruption beyond the null pointer dereference, nor any possibility of code execution, was observed.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Double Free

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocations array. As a result, process_got_section_contents() may pass an uninitialized r_symbol pointer to free(), leading to a double free and terminating the program with SIGABRT. No evidence of exploitable memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability, which was classified as problematic, was found in GNU Binutils up to 2.43. This affects the function disassemble_bytes of the file binutils/objdump.c. The manipulation of the argument buf leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. The identifier of the patch is baac6c221e9d69335bf41366a1c7d87d8ab2f893. It is recommended to upgrade the affected component.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.43. It has been rated as critical. Affected by this issue is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. The manipulation leads to memory corruption. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 2.44 is able to address this issue. It is recommended to upgrade the affected component. The code maintainer explains, that "[t]his bug has been fixed at some point between the 2.43 and 2.44 releases".

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Cleartext Transmission of Sensitive Information

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Using libcurl, when a custom Host: header is first set for an HTTP request and a second request is subsequently done using the same easy handle but without the custom Host: header set, the second request would use stale information and pass on cookies meant for the first host in the second request. Leak them.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Out-of-Bounds

  • Vulnerable module: elfutils/libelf1
  • Introduced through: elfutils/libelf1@0.188-2.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › elfutils/libelf1@0.188-2.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream elfutils package and not the elfutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability has been found in GNU elfutils 0.192 and classified as critical. This vulnerability affects the function __libdw_thread_tail in the library libdw_alloc.c of the component eu-readelf. The manipulation of the argument w leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 2636426a091bd6c6f7f02e49ab20d4cdc6bfc753. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 elfutils.

References

low severity

Algorithmic Complexity

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libexpat before 2.8.1, the computational complexity of attribute name collision checks allows a denial of service via moderately sized crafted XML input.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Algorithmic Complexity

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, where processing N specified attributes with non-normalized values triggers an O(N^2) linear scan of elementType->defaultAtts to determine CDATA status. A remote unauthenticated attacker can supply a single well-formed XML document of a few megabytes to an application parsing untrusted XML to cause excessive CPU consumption, resulting in denial of service without requiring authentication, external entity resolution, or non-default parser options.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Exposure of Resource to Wrong Sphere

  • Vulnerable module: git
  • Introduced through: git@1:2.39.5-0+deb12u3 and git/git-man@1:2.39.5-0+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › git@1:2.39.5-0+deb12u3
  • Introduced through: buildpack-deps@bookworm › git/git-man@1:2.39.5-0+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream git package and not the git package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The --mirror documentation for Git through 2.35.1 does not mention the availability of deleted content, aka the "GitBleed" issue. This could present a security risk if information-disclosure auditing processes rely on a clone operation without the --mirror option. Note: This has been disputed by multiple 3rd parties who believe this is an intended feature of the git binary and does not pose a security risk.

Remediation

There is no fixed version for Debian:12 git.

References

low severity

Directory Traversal

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GLib. The D-Bus client-side implementation of the DBUS_COOKIE_SHA1 SASL authentication mechanism does not validate the cookie_context parameter received from the server. A malicious D-Bus server can supply a cookie_context containing path traversal sequences, causing the client to read an arbitrary file and exfiltrate sensitive data by verifying guessed file contents against a generated hash.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Out-of-bounds Read

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the glib/gdatetime.c file when an invalid GDateTime object produced by the g_date_time_add_full function is processed. This flaw can corrupt the date output and potentially cause logic errors that may lead to a denial of service.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Uncontrolled Recursion

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(\227|)(\1\1|t1|\\2537)+' in grep.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

Uncontrolled Recursion

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In the GNU C Library (aka glibc or libc6) through 2.29, check_dst_limits_calc_pos_1 in posix/regexec.c has Uncontrolled Recursion, as demonstrated by '(|)(\1\1)*' in grep, a different issue than CVE-2018-20796. NOTE: the software maintainer disputes that this is a vulnerability because the behavior occurs only with a crafted pattern

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

Buffer Over-read

  • Vulnerable module: gzip
  • Introduced through: gzip@1.12-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gzip@1.12-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream gzip package and not the gzip package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.

This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.

Remediation

There is no fixed version for Debian:12 gzip.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: harfbuzz/libharfbuzz0b
  • Introduced through: harfbuzz/libharfbuzz0b@6.0.0+dfsg-3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › harfbuzz/libharfbuzz0b@6.0.0+dfsg-3

NVD Description

Note: Versions mentioned in the description apply only to the upstream harfbuzz package and not the harfbuzz package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

Remediation

There is no fixed version for Debian:12 harfbuzz.

References

low severity
new

Resource Exhaustion

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in the MSL image decoder. A crafted MSL image triggers memory allocation without proper deallocation, allowing an attacker to exhaust memory and cause a denial of service.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity
new

Resource Exhaustion

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the memory budget when an operation inside OpenPixelCache fails. Repeated triggering of such failures can exhaust the process memory budget and result in a denial of service.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: krb5/krb5-multidev
  • Introduced through: krb5/krb5-multidev@1.20.1-2+deb12u5, krb5/libgssapi-krb5-2@1.20.1-2+deb12u5 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › krb5/krb5-multidev@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libgssapi-krb5-2@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libgssrpc4@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libk5crypto3@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkadm5clnt-mit12@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkadm5srv-mit12@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkdb5-10@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5-3@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5-dev@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5support0@1.20.1-2+deb12u5

NVD Description

Note: Versions mentioned in the description apply only to the upstream krb5 package and not the krb5 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in MIT Kerberos 5 (aka krb5) through 1.16. There is a variable "dbentry->n_key_data" in kadmin/dbutil/dump.c that can store 16-bit data but unknowingly the developer has assigned a "u4" variable to it, which is for 32-bit data. An attacker can use this vulnerability to affect other artifacts of the database as we know that a Kerberos database dump file contains trusted data.

Remediation

There is no fixed version for Debian:12 krb5.

References

low severity

Use of a Broken or Risky Cryptographic Algorithm

  • Vulnerable module: libgcrypt20
  • Introduced through: libgcrypt20@1.10.1-3+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libgcrypt20@1.10.1-3+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libgcrypt20 package and not the libgcrypt20 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.

Remediation

There is no fixed version for Debian:12 libgcrypt20.

References

low severity

Use of Uninitialized Variable

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In versions 3.3.0 through 3.3.5 and 3.4.0 through 3.4.2, while fuzzing openexr_exrcheck_fuzzer, Valgrind reports a conditional branch depending on uninitialized data inside generic_unpack. This indicates a use of uninitialized memory. The issue can result in undefined behavior and/or a potential crash/denial of service. Versions 3.3.6 and 3.4.3 fix the issue.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

There is a NULL Pointer Access in function imagetopnm of convert.c:1943(jp2) of OpenJPEG 2.1.2. image->comps[compno].data is not assigned a value after initialization(NULL). Impact is Denial of Service.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

There is a NULL pointer dereference in function imagetobmp of convertbmp.c:980 of OpenJPEG 2.1.2. image->comps[0].data is not assigned a value after initialization(NULL). Impact is Denial of Service.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Cryptographic Issues

  • Vulnerable module: openldap/libldap-2.5-0
  • Introduced through: openldap/libldap-2.5-0@2.5.13+dfsg-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openldap/libldap-2.5-0@2.5.13+dfsg-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openldap package and not the openldap package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The nss_parse_ciphers function in libraries/libldap/tls_m.c in OpenLDAP does not properly parse OpenSSL-style multi-keyword mode cipher strings, which might cause a weaker than intended cipher to be used and allow remote attackers to have unspecified impact via unknown vectors.

Remediation

There is no fixed version for Debian:12 openldap.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: openldap/libldap-2.5-0
  • Introduced through: openldap/libldap-2.5-0@2.5.13+dfsg-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openldap/libldap-2.5-0@2.5.13+dfsg-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openldap package and not the openldap package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.

Remediation

There is no fixed version for Debian:12 openldap.

References

low severity

Out-of-Bounds

  • Vulnerable module: openldap/libldap-2.5-0
  • Introduced through: openldap/libldap-2.5-0@2.5.13+dfsg-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openldap/libldap-2.5-0@2.5.13+dfsg-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openldap package and not the openldap package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

contrib/slapd-modules/nops/nops.c in OpenLDAP through 2.4.45, when both the nops module and the memberof overlay are enabled, attempts to free a buffer that was allocated on the stack, which allows remote attackers to cause a denial of service (slapd crash) via a member MODDN operation.

Remediation

There is no fixed version for Debian:12 openldap.

References

low severity

Double Free

  • Vulnerable module: patch
  • Introduced through: patch@2.7.6-7

Detailed paths

  • Introduced through: buildpack-deps@bookworm › patch@2.7.6-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream patch package and not the patch package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A double free exists in the another_hunk function in pch.c in GNU patch through 2.7.6.

Remediation

There is no fixed version for Debian:12 patch.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: patch
  • Introduced through: patch@2.7.6-7

Detailed paths

  • Introduced through: buildpack-deps@bookworm › patch@2.7.6-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream patch package and not the patch package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in GNU patch through 2.7.6. There is a segmentation fault, associated with a NULL pointer dereference, leading to a denial of service in the intuit_diff_type function in pch.c, aka a "mangled rename" issue.

Remediation

There is no fixed version for Debian:12 patch.

References

low severity

CVE-2026-42497

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory.

_make_special_file() passes the tar header's linkname to link() without validating it against absolute paths or .. segments, creating a hardlink that shares the victim file's inode.

A subsequent write through the extracted name modifies the victim file, and the post-extraction chmod, chown, and utime block in _extract_file() (guarded only against symlinks via -l) applies the tar header's mode, owner, and timestamps to the shared inode during extraction alone.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-9538

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.

_read_tar() reads each entry's payload with $handle->read($$data, $block), where $block is derived from the entry's 12-byte size field in the tar header with no upper bound on that value.

A crafted header declaring a multi-gigabyte size causes Perl to allocate a scalar of that size.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2025-69534

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Python-Markdown version 3.8 contain a vulnerability where malformed HTML-like sequences can cause html.parser.HTMLParser to raise an unhandled AssertionError during Markdown parsing. Because Python-Markdown does not catch this exception, any application that processes attacker-controlled Markdown may crash. This enables remote, unauthenticated Denial of Service in web applications, documentation systems, CI/CD pipelines, and any service that renders untrusted Markdown. The issue was acknowledged by the vendor and fixed in version 3.8.1. This issue causes a remote Denial of Service in any application parsing untrusted Markdown, and can lead to Information Disclosure through uncaught exceptions.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-3644

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update(), |= operator, and unpickling paths were not patched, allowing control characters to bypass input validation. Additionally, BaseCookie.js_output() lacked the output validation applied to BaseCookie.output().

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-7210

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

xml.parsers.expat and xml.etree.ElementTree use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this vulnerability requires both updating libexpat to 2.8.0 or later and applying this patch.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

Missing Release of Resource after Effective Lifetime

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Out-of-bounds Write

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 KB.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Out-of-bounds Read

  • Vulnerable module: wget
  • Introduced through: wget@1.21.3-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › wget@1.21.3-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream wget package and not the wget package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.

Remediation

There is no fixed version for Debian:12 wget.

References

low severity

OS Command Injection

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that they intentionally omit validation of "anomalous argument transfers" because that could "stand a great chance of breaking existing workflows."

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

CVE-2008-1687

  • Vulnerable module: m4
  • Introduced through: m4@1.4.19-3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › m4@1.4.19-3

NVD Description

Note: Versions mentioned in the description apply only to the upstream m4 package and not the m4 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The (1) maketemp and (2) mkstemp builtin functions in GNU m4 before 1.4.11 do not quote their output when a file is created, which might allow context-dependent attackers to trigger a macro expansion, leading to unspecified use of an incorrect filename.

Remediation

There is no fixed version for Debian:12 m4.

References

low severity

CVE-2008-1688

  • Vulnerable module: m4
  • Introduced through: m4@1.4.19-3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › m4@1.4.19-3

NVD Description

Note: Versions mentioned in the description apply only to the upstream m4 package and not the m4 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Unspecified vulnerability in GNU m4 before 1.4.11 might allow context-dependent attackers to execute arbitrary code, related to improper handling of filenames specified with the -F option. NOTE: it is not clear when this issue crosses privilege boundaries.

Remediation

There is no fixed version for Debian:12 m4.

References

low severity

Out-of-Bounds

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libtiff up to v4.7.1 was discovered to contain a stack overflow via the readSeparateStripsIntoBuffer function.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Link Following

  • Vulnerable module: acl/libacl1
  • Introduced through: acl/libacl1@2.3.1-3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › acl/libacl1@2.3.1-3

NVD Description

Note: Versions mentioned in the description apply only to the upstream acl package and not the acl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.

Remediation

There is no fixed version for Debian:12 acl.

References

low severity

Link Following

  • Vulnerable module: attr/libattr1
  • Introduced through: attr/libattr1@1:2.5.1-4

Detailed paths

  • Introduced through: buildpack-deps@bookworm › attr/libattr1@1:2.5.1-4

NVD Description

Note: Versions mentioned in the description apply only to the upstream attr package and not the attr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.

Remediation

There is no fixed version for Debian:12 attr.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GNU Binutils. This heap-based buffer overflow vulnerability, specifically an out-of-bounds read in the bfd linker, allows an attacker to gain access to sensitive information. By convincing a user to process a specially crafted XCOFF object file, an attacker can trigger this flaw, potentially leading to information disclosure or an application level denial of service.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GNU Binutils. This vulnerability, a heap-based buffer overflow, specifically an out-of-bounds read, exists in the bfd linker component. An attacker could exploit this by convincing a user to process a specially crafted malicious XCOFF object file. Successful exploitation may lead to the disclosure of sensitive information or cause the application to crash, resulting in an application level denial of service.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little-endian systems when an attacker-controlled MIME magic file in a user-writable XDG data location (e.g., in the $XDG_DATA_HOME/mime/magic path) is parsed by an application performing MIME type detection (e.g., via g_content_type_guess()). When performing byte-swap, incorrect pointer arithmetic on the write side causes an out-of-bounds write of 2 bytes, resulting in an application crash or memory corruption.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is an HEIF and AVIF file format decoder and encoder. Prior to version 1.21.0, a crafted HEIF that exercises the overlay image item path triggers a heap buffer over-read in HeifPixelImage::overlay(). The function computes a negative row length (likely from an unclipped overlay rectangle or invalid offsets), which then underflows when converted to size_t and is passed to memcpy, causing a very large read past the end of the source plane and a crash. Version 1.21.0 contains a patch. As a workaround, avoid decoding images using iovl overlay boxes.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A security vulnerability has been detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_64_relocate_section of the file bfd/elf64-x86-64.c of the component ld. Such manipulation of the argument roff leads to buffer overflow. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 addresses this issue. The name of the patch is 471130b39c03623ec6d78ece377ff4da3f6bfe7b. It is recommended to upgrade the affected component.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Inappropriate Encoding for Output Context

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In OpenSSH 7.9, due to accepting and displaying arbitrary stderr output from the server, a malicious server (or Man-in-The-Middle attacker) can manipulate the client output, for example to use ANSI control codes to hide additional files being transferred.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity
new

Improper Resource Shutdown or Release

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A security flaw has been discovered in GNU Binutils 2.47. This vulnerability affects the function elf_orphan_compatible of the file ld/ldelf.c of the component ELF Orphan Section Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity
new

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A security flaw has been discovered in GNU Binutils 2.47. This impacts the function cache_bwrite of the file bfd/cache.c of the component ld. The manipulation of the argument nbytes results in buffer overflow. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A heap-based buffer over-read exists in the function d_expression_1 in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31.1. A crafted input can cause segmentation faults, leading to denial-of-service, as demonstrated by c++filt.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Write

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A potential heap based buffer overflow was found in _bfd_elf_slurp_version_tables() in bfd/elf.c. This may lead to loss of availability.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Write

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in GNU libiberty, as distributed in GNU Binutils 2.36. It is a stack-overflow issue in demangle_type in rust-demangle.c.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Loop with Unreachable Exit Condition ('Infinite Loop')

  • Vulnerable module: cairo/libcairo-gobject2
  • Introduced through: cairo/libcairo-gobject2@1.16.0-7, cairo/libcairo-script-interpreter2@1.16.0-7 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-gobject2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-script-interpreter2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2-dev@1.16.0-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream cairo package and not the cairo package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in cairo 1.16.0. There is an infinite loop in the function _arc_error_normalized in the file cairo-arc.c, related to _arc_max_angle_for_tolerance_normalized.

Remediation

There is no fixed version for Debian:12 cairo.

References

low severity

Out-of-bounds Write

  • Vulnerable module: cairo/libcairo-gobject2
  • Introduced through: cairo/libcairo-gobject2@1.16.0-7, cairo/libcairo-script-interpreter2@1.16.0-7 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-gobject2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-script-interpreter2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2-dev@1.16.0-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream cairo package and not the cairo package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

cairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the interaction between cairo-rectangular-scan-converter.c (the generate and render_rows functions) and cairo-image-compositor.c (the _cairo_image_spans_and_zero function).

Remediation

There is no fixed version for Debian:12 cairo.

References

low severity

Reachable Assertion

  • Vulnerable module: cairo/libcairo-gobject2
  • Introduced through: cairo/libcairo-gobject2@1.16.0-7, cairo/libcairo-script-interpreter2@1.16.0-7 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-gobject2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-script-interpreter2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2-dev@1.16.0-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream cairo package and not the cairo package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in cairo 1.16.0. There is an assertion problem in the function _cairo_arc_in_direction in the file cairo-arc.c.

Remediation

There is no fixed version for Debian:12 cairo.

References

low severity

Improper Input Validation

  • Vulnerable module: coreutils
  • Introduced through: coreutils@9.1-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › coreutils@9.1-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream coreutils package and not the coreutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

chroot in GNU coreutils, when used with --userspec, allows local users to escape to the parent session via a crafted TIOCSTI ioctl call, which pushes characters to the terminal's input buffer.

Remediation

There is no fixed version for Debian:12 coreutils.

References

low severity

Insufficient Session Expiration

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libcurl might in some circumstances reuse the wrong connection when asked to do an authenticated HTTP(S) request after a Negotiate-authenticated one, when both use the same host.

libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.

When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials.

An application that first uses Negotiate authentication to a server with user1:password1 and then does another operation to the same server asking for any authentication method but for user2:password2 (while the previous connection is still alive) - the second request gets confused and wrongly reuses the same connection and sends the new request over that connection thinking it uses a mix of user1's and user2's credentials when it is in fact still using the connection authenticated for user1...

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Missing Release of Resource after Effective Lifetime

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an AcquireSemaphoreInfo call.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Missing Release of Resource after Effective Lifetime

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The WritePICONImage function in coders/xpm.c in ImageMagick 7.0.6-4 allows remote attackers to cause a denial of service (memory leak) via a crafted file that is mishandled in an OpenPixelCache call.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Resource Exhaustion

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00 can result in a hang of several minutes during which CPU and memory resources are consumed until ultimately an attempted large memory allocation fails. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted file.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Out-of-Bounds

  • Vulnerable module: jbigkit/libjbig-dev
  • Introduced through: jbigkit/libjbig-dev@2.1-6.1 and jbigkit/libjbig0@2.1-6.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › jbigkit/libjbig-dev@2.1-6.1
  • Introduced through: buildpack-deps@bookworm › jbigkit/libjbig0@2.1-6.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream jbigkit package and not the jbigkit package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In LibTIFF 4.0.8, there is a memory malloc failure in tif_jbig.c. A crafted TIFF document can lead to an abort resulting in a remote denial of service attack.

Remediation

There is no fixed version for Debian:12 jbigkit.

References

low severity

CVE-2023-50495

  • Vulnerable module: ncurses/libncurses-dev
  • Introduced through: ncurses/libncurses-dev@6.4-4, ncurses/libncurses5-dev@6.4-4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses5-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncursesw5-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncursesw6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libtinfo6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/ncurses-base@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/ncurses-bin@6.4-4

NVD Description

Note: Versions mentioned in the description apply only to the upstream ncurses package and not the ncurses package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

NCurse v6.4-20230418 was discovered to contain a segmentation fault via the component _nc_wrap_entry().

Remediation

There is no fixed version for Debian:12 ncurses.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in OpenJPEG 2.3.0. It allows remote attackers to cause a denial of service (attempted excessive memory allocation) in opj_calloc in openjp2/opj_malloc.c, when called from opj_tcd_init_tile in openjp2/tcd.c, as demonstrated by the 64-bit opj_decompress.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

NULL Pointer Access in function imagetopnm of convert.c:2226(jp2) in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

NULL pointer dereference vulnerabilities in the imagetopnm function in convert.c, sycc444_to_rgb function in color.c, color_esycc_to_rgb function in color.c, and sycc422_to_rgb function in color.c in OpenJPEG before 2.2.0 allow remote attackers to cause a denial of service (application crash) via crafted j2k files.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

NULL Pointer Access in function imagetopnm of convert.c(jp2):1289 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Out-of-Bounds

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Heap Buffer Over-read in function imagetotga of convert.c(jp2):942 in OpenJPEG 2.1.2. Impact is Denial of Service. Someone must open a crafted j2k file.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Divide By Zero

  • Vulnerable module: pixman/libpixman-1-0
  • Introduced through: pixman/libpixman-1-0@0.42.2-1 and pixman/libpixman-1-dev@0.42.2-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › pixman/libpixman-1-0@0.42.2-1
  • Introduced through: buildpack-deps@bookworm › pixman/libpixman-1-dev@0.42.2-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream pixman package and not the pixman package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combine-float.c.

Remediation

There is no fixed version for Debian:12 pixman.

References

low severity

Improper Resource Shutdown or Release

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as problematic was found in LibTIFF 4.3.0. Affected by this vulnerability is the TIFF File Handler of tiff2ps. Opening a malicious file leads to a denial of service. The attack can be launched remotely but requires user interaction. The exploit has been disclosed to the public and may be used.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Resource Exhaustion

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Time-of-check Time-of-use (TOCTOU)

  • Vulnerable module: acl/libacl1
  • Introduced through: acl/libacl1@2.3.1-3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › acl/libacl1@2.3.1-3

NVD Description

Note: Versions mentioned in the description apply only to the upstream acl package and not the acl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.

Remediation

There is no fixed version for Debian:12 acl.

References

low severity

Numeric Errors

  • Vulnerable module: libwmf/libwmf-0.2-7
  • Introduced through: libwmf/libwmf-0.2-7@0.2.12-5.1, libwmf/libwmf-dev@0.2.12-5.1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libwmf/libwmf-0.2-7@0.2.12-5.1
  • Introduced through: buildpack-deps@bookworm › libwmf/libwmf-dev@0.2.12-5.1
  • Introduced through: buildpack-deps@bookworm › libwmf/libwmflite-0.2-7@0.2.12-5.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libwmf package and not the libwmf package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Multiple integer overflows in libgd in PHP before 5.2.4 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large (1) srcW or (2) srcH value to the (a) gdImageCopyResized function, or a large (3) sy (height) or (4) sx (width) value to the (b) gdImageCreate or the (c) gdImageCreateTrueColor function.

Remediation

There is no fixed version for Debian:12 libwmf.

References

low severity

Access Restriction Bypass

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain access to arbitrary SELinux roles by appending a :/ (colon slash) sequence, followed by the role name, to the username.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: p11-kit/libp11-kit0
  • Introduced through: p11-kit/libp11-kit0@0.24.1-2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › p11-kit/libp11-kit0@0.24.1-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream p11-kit package and not the p11-kit package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in p11-kit. A local attacker, or one with equivalent access to a reachable RPC channel, could exploit an integer overflow vulnerability. By sending specially crafted messages, the attacker can cause the system to miscalculate memory allocation for nested attributes. This leads to a memory corruption issue, specifically a heap out-of-bounds write, which can crash the p11-kit RPC parsing process, resulting in a Denial of Service (DoS). This vulnerability is only exploitable on 32 bit systems.

Remediation

There is no fixed version for Debian:12 p11-kit.

References

low severity

Uncontrolled Recursion

  • Vulnerable module: p11-kit/libp11-kit0
  • Introduced through: p11-kit/libp11-kit0@0.24.1-2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › p11-kit/libp11-kit0@0.24.1-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream p11-kit package and not the p11-kit package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.

Remediation

There is no fixed version for Debian:12 p11-kit.

References

low severity

Access Restriction Bypass

  • Vulnerable module: shadow/login
  • Introduced through: shadow/login@1:4.13+dfsg1-1+deb12u2 and shadow/passwd@1:4.13+dfsg1-1+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › shadow/login@1:4.13+dfsg1-1+deb12u2
  • Introduced through: buildpack-deps@bookworm › shadow/passwd@1:4.13+dfsg1-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream shadow package and not the shadow package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

initscripts in rPath Linux 1 sets insecure permissions for the /var/log/btmp file, which allows local users to obtain sensitive information regarding authentication attempts. NOTE: because sshd detects the insecure permissions and does not log certain events, this also prevents sshd from logging failed authentication attempts by remote attackers.

Remediation

There is no fixed version for Debian:12 shadow.

References

low severity
new

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was detected in GNU Binutils 2.47. Affected by this issue is the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component Eh Frame Section Handler. Performing a manipulation of the argument cie_length/fde_length/augmentation_data_size/write_offset results in buffer overflow. Attacking locally is a requirement. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: coreutils
  • Introduced through: coreutils@9.1-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › coreutils@9.1-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream coreutils package and not the coreutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU coreutils unexpand is vulnerable to a heap-based buffer overflow due to an integer overflow during buffer allocation when processing large tab stop (-t) values. The multiplication used to calculate the allocation size can wrap around, resulting in an undersized buffer. When processing crafted input, subsequent writes exceed the allocated memory, leading to an out‑of‑bounds heap write.

When running GNU coreutils unexpand with attacker-provided large tab stop (-t) arguments, this behavior leads to a crash and potentially achieve a heap write primitive depending on memory layout.

This issue has been fixed in the commit b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d

Remediation

There is no fixed version for Debian:12 coreutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: coreutils
  • Introduced through: coreutils@9.1-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › coreutils@9.1-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream coreutils package and not the coreutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU coreutils uniq is vulnerable to an out‑of‑bounds read due to incorrect handling of multibyte input when the -w (--check-chars) option is used. The find_field() function miscalculates the byte length of characters by repeatedly processing a fixed pointer instead of advancing through the input, resulting in an inflated length value. This incorrect length is later used in a memcmp operation, causing reads beyond the allocated buffer when processing crafted multibyte input.

When running GNU coreutils uniq with attacker-provided arguments, this behavior leads to a crash and potential adjacent heap memory exposure.

This issue has been fixed in the commit d64e35a8a4c0e4608321433e0d84d917e4e36371.

Remediation

There is no fixed version for Debian:12 coreutils.

References

low severity
new

Out-of-bounds Read

  • Vulnerable module: gdk-pixbuf/gir1.2-gdkpixbuf-2.0
  • Introduced through: gdk-pixbuf/gir1.2-gdkpixbuf-2.0@2.42.10+dfsg-1+deb12u4, gdk-pixbuf/libgdk-pixbuf-2.0-0@2.42.10+dfsg-1+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/gir1.2-gdkpixbuf-2.0@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf-2.0-0@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf-2.0-dev@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf2.0-bin@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf2.0-common@2.42.10+dfsg-1+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream gdk-pixbuf package and not the gdk-pixbuf package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() function, which handles RLE-encoded ICNS icon data, fails to validate the source buffer's boundaries during decompression. This can lead to a denial of service, where the application crashes, or to information disclosure, potentially revealing sensitive data from adjacent memory.

Remediation

There is no fixed version for Debian:12 gdk-pixbuf.

References

low severity

Improper Encoding or Escaping of Output

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It does not neutralize the HTML parser-sensitive sequence </script> inside the generated script element. Mitigation base64-encodes the cookie value to disallow escaping using cookie value.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

Out-of-bounds Read

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in tiffcrop, a program distributed by the libtiff package. A specially crafted tiff file can lead to an out-of-bounds read in the extractImageSection function in tools/tiffcrop.c, resulting in a denial of service and limited information disclosure. This issue affects libtiff versions 4.x.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Out-of-bounds Read

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, specifically within the setpwnam() function, affecting SUID (Set User ID) login-utils utilities writing to the password database.

Remediation

There is no fixed version for Debian:12 util-linux.

References

low severity

Open Redirect

  • Vulnerable module: wget
  • Introduced through: wget@1.21.3-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › wget@1.21.3-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream wget package and not the wget package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Wget through 1.21.1 does not omit the Authorization header upon a redirect to a different origin, a related issue to CVE-2018-1000007.

Remediation

There is no fixed version for Debian:12 wget.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as problematic was found in GNU Binutils 2.43/2.44. Affected by this vulnerability is the function bfd_set_format of the file format.c. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. Upgrading to version 2.45 is able to address this issue. The identifier of the patch is 8d97c1a53f3dc9fd8e1ccdb039b8a33d50133150. It is recommended to upgrade the affected component.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Race Condition

  • Vulnerable module: dav1d/libdav1d6
  • Introduced through: dav1d/libdav1d6@1.0.0-2+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › dav1d/libdav1d6@1.0.0-2+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream dav1d package and not the dav1d package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.

Remediation

There is no fixed version for Debian:12 dav1d.

References

low severity

Information Exposure

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The client side in OpenSSH 5.7 through 8.4 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the server has been cached by the client). NOTE: some reports state that 8.5 and 8.6 are also affected.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: wget
  • Introduced through: wget@1.21.3-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › wget@1.21.3-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream wget package and not the wget package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.

Remediation

There is no fixed version for Debian:12 wget.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. Affected by this vulnerability is the function bfd_putl64 of the file libbfd.c of the component ld. The manipulation leads to memory corruption. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The identifier of the patch is 75086e9de1707281172cc77f178e7949a4414ed0. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in the GNU Binutils (Binary Utilities) linker. This vulnerability, a heap-buffer-overflow read (CWE-125), occurs when the linker processes a specially crafted 32-bit XCOFF (Extended Common Object File Format) object file. An attacker could exploit this by providing a malicious file, leading to an out-of-bounds read of memory. This can result in information disclosure, potentially revealing sensitive heap data, and a Denial of Service (DoS) due to the linker crashing.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The C++ symbol demangler routine in cplus-dem.c in libiberty, as distributed in GNU Binutils 2.29, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted file, as demonstrated by a call from the Binary File Descriptor (BFD) library (aka libbfd).

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-69651

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an invalid pointer free when processing a crafted ELF binary with malformed relocation or symbol data. If dump_relocations returns early due to parsing errors, the internal all_relocations array may remain partially uninitialized. Later, process_got_section_contents() may attempt to free an invalid r_symbol pointer, triggering memory corruption checks in glibc and causing the program to terminate with SIGABRT. No evidence of further memory corruption or code execution was observed; the impact is limited to denial of service. NOTE: this is disputed by third parties because the observed behavior occurred only in pre-release code and did not affect any tagged version.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Memory Leak

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory leak. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is named ba6ad3a18cb26b79e0e3b84c39f707535bbc344d. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability has been found in GNU Binutils 2.44 and classified as problematic. This vulnerability affects the function bfd_elf_get_str_section of the file bfd/elf.c of the component BFD Library. The manipulation leads to null pointer dereference. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The name of the patch is db856d41004301b3a56438efd957ef5cabb91530. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was detected in GNU Binutils 2.45. This issue affects the function dump_dwarf_section of the file binutils/objdump.c. Performing manipulation results in out-of-bounds read. The attack is only possible with local access. The exploit is now public and may be used. The patch is named f87a66db645caf8cc0e6fc87b0c28c78a38af59b. It is suggested to install a patch to address this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was determined in GNU Binutils 2.45. The affected element is the function elf_x86_64_relocate_section of the file elf64-x86-64.c of the component Linker. This manipulation causes heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Patch name: 6b21c8b2ecfef5c95142cbc2c32f185cb1c26ab0. To fix this issue, it is recommended to deploy a patch.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.45. Affected is the function elf_link_add_object_symbols of the file bfd/elflink.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. Upgrading to version 2.46 is able to address this issue. The patch is identified as 72efdf166aa0ed72ecc69fc2349af6591a7a19c0. Upgrading the affected component is advised.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was determined in GNU Binutils 2.45. Affected by this vulnerability is the function get_link_hash_entry of the file bfd/elflink.c of the component Linker. This manipulation causes out-of-bounds read. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. Upgrading to version 2.46 addresses this issue. Patch name: aeaaa9af6359c8e394ce9cf24911fec4f4d23703. It is advisable to upgrade the affected component.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability has been found in GNU Binutils 2.45. This impacts the function bfd_elf_gc_record_vtentry of the file bfd/elflink.c of the component Linker. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier of the patch is 047435dd988a3975d40c6626a8f739a0b2e154bc. To fix this issue, it is recommended to deploy a patch.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.45. Impacted is the function _bfd_x86_elf_late_size_sections of the file bfd/elfxx-x86.c of the component Linker. The manipulation results in out-of-bounds read. The attack needs to be approached locally. The exploit has been made public and could be used. The patch is identified as b6ac5a8a5b82f0ae6a4642c8d7149b325f4cc60a. A patch should be applied to remediate this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A weakness has been identified in GNU Binutils 2.45. The affected element is the function vfinfo of the file ldmisc.c. Executing a manipulation can lead to out-of-bounds read. The attack can only be executed locally. The exploit has been made available to the public and could be used for attacks. This patch is called 16357. It is best practice to apply a patch to resolve this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Write

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The demangle_template function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31.1, contains an integer overflow vulnerability (for "Create an array for saving the template argument values") that can trigger a heap-based buffer overflow, as demonstrated by nm.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Resource Exhaustion

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in the readelf utility of the binutils package. A local attacker could exploit two Denial of Service (DoS) vulnerabilities by providing a specially crafted Executable and Linkable Format (ELF) file. One vulnerability, a resource exhaustion (CWE-400), can lead to an out-of-memory condition. The other, a null pointer dereference (CWE-476), can cause a segmentation fault. Both issues can result in the readelf utility becoming unresponsive or crashing, leading to a denial of service.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Unchecked Return Value

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A security flaw has been discovered in GNU Binutils 2.45. Impacted is the function tg_tag_type of the file prdbg.c. Performing a manipulation results in unchecked return value. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Uncontrolled Recursion

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_template_value_parm, demangle_integral_value, and demangle_expression.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Use After Free

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils. The root cause is that plugin_maybe_claim() in ld/plugin.c frees the original BFD object via bfd_close/_bfd_delete_bfd when entry->the_bfd->my_archive == NULL, but the caller retains both the original abfd parameter and a shallow copy (orig_input.the_bfd) as dangling pointers. These dangling pointers are subsequently dereferenced at three distinct locations in add_archive_element:

  1. Line ~1442: accessing abfd->my_archive via bfd_usrdata(abfd->my_archive)
  2. Line ~1493: multiple accesses to abfd and abfd->my_archive in a conditional check and bfd_get_filename call
  3. Line ~1525: dereferencing the shallow copy orig_input.the_bfd->my_archive in trace/verbose logging

The vulnerability is triggered when LTO plugins are active (link_info.lto_plugin_active is true) and the input object has abfd->my_archive == NULL, which is a valid state for standalone object files. Red Hat builds binutils with --enable-plugins and --enable-lto, confirming the vulnerable code path is compiled in and reachable.

An attacker who can supply a crafted object or archive file to a build process using LTO-enabled linking could exploit this flaw to cause a denial of service (linker crash via segmentation fault). Arbitrary code execution is theoretically possible through heap manipulation but is substantially mitigated by hardening measures including stack protector, FORTIFY_SOURCE, ASLR, and PIE.

The attack surface is limited to build-time environments — the linker is a development tool not exposed in production runtime. The most realistic exploitation scenario is a supply chain attack introducing a crafted object file as a build dependency in CI/CD pipelines or development environments.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: cairo/libcairo-gobject2
  • Introduced through: cairo/libcairo-gobject2@1.16.0-7, cairo/libcairo-script-interpreter2@1.16.0-7 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-gobject2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-script-interpreter2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2-dev@1.16.0-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream cairo package and not the cairo package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Cairo version 1.15.4 is vulnerable to a NULL pointer dereference related to the FT_Load_Glyph and FT_Render_Glyph resulting in an application crash.

Remediation

There is no fixed version for Debian:12 cairo.

References

low severity

Improper Resource Shutdown or Release

  • Vulnerable module: elfutils/libelf1
  • Introduced through: elfutils/libelf1@0.188-2.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › elfutils/libelf1@0.188-2.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream elfutils package and not the elfutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability, which was classified as problematic, has been found in GNU elfutils 0.192. This issue affects the function gelf_getsymshndx of the file strip.c of the component eu-strip. The manipulation leads to denial of service. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is fbf1df9ca286de3323ae541973b08449f8d03aba. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 elfutils.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: elfutils/libelf1
  • Introduced through: elfutils/libelf1@0.188-2.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › elfutils/libelf1@0.188-2.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream elfutils package and not the elfutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability has been found in GNU elfutils 0.192 and classified as problematic. This vulnerability affects the function handle_dynamic_symtab of the file readelf.c of the component eu-read. The manipulation leads to null pointer dereference. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The patch is identified as b38e562a4c907e08171c76b8b2def8464d5a104a. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 elfutils.

References

low severity

Algorithmic Complexity

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing time.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libexpat through 2.5.0 allows recursive XML Entity Expansion if XML_DTD is undefined at compile time.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Loop with Unreachable Exit Condition ('Infinite Loop')

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libexpat before 2.7.5 allows an infinite loop while parsing DTD content.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libexpat before 2.7.5 allows a NULL pointer dereference in the function setContext on retry after an earlier ouf-of-memory condition.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libexpat before 2.7.5 allows a NULL pointer dereference with empty external parameter entity content.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Uncontrolled Recursion

  • Vulnerable module: gcc-12
  • Introduced through: gcc-12@12.2.0-14+deb12u1, gcc-12/cpp-12@12.2.0-14+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gcc-12@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/cpp-12@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/g++-12@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/gcc-12-base@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libasan8@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libatomic1@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libcc1-0@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libgcc-12-dev@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libgcc-s1@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libgomp1@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libitm1@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/liblsan0@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libquadmath0@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libstdc++-12-dev@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libstdc++6@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libtsan2@12.2.0-14+deb12u1
  • Introduced through: buildpack-deps@bookworm › gcc-12/libubsan1@12.2.0-14+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream gcc-12 package and not the gcc-12 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

Remediation

There is no fixed version for Debian:12 gcc-12.

References

low severity

CVE-2005-0406

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Out-of-Bounds

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The ReadPCXImage function in coders/pcx.c in ImageMagick 7.0.4.9 allows remote attackers to cause a denial of service (attempted large memory allocation and application crash) via a crafted file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862 and CVE-2016-8866.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Out-of-bounds Read

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says "This is a Q64 issue and we do not support Q64."

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity
new

Use After Free

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the GetList method of PerlMagick. A crafted call to the GetList method can trigger the use-after-free, resulting in a crash (denial of service).

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity
new

Use After Free

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap-use-after-free vulnerability in the Layer method of PerlMagick. An attacker who supplies a crafted list of images can trigger memory access after deallocation, resulting in a crash (denial of service).

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Buffer Overflow

  • Vulnerable module: libpng1.6/libpng-dev
  • Introduced through: libpng1.6/libpng-dev@1.6.39-2+deb12u5 and libpng1.6/libpng16-16@1.6.39-2+deb12u5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng-dev@1.6.39-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng16-16@1.6.39-2+deb12u5

NVD Description

Note: Versions mentioned in the description apply only to the upstream libpng1.6 package and not the libpng1.6 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A heap overflow flaw was found in libpngs' pngimage.c program. This flaw allows an attacker with local network access to pass a specially crafted PNG file to the pngimage utility, causing an application to crash, leading to a denial of service.

Remediation

There is no fixed version for Debian:12 libpng1.6.

References

low severity

Expired Pointer Dereference

  • Vulnerable module: libxslt/libxslt1-dev
  • Introduced through: libxslt/libxslt1-dev@1.1.35-1+deb12u4 and libxslt/libxslt1.1@1.1.35-1+deb12u4

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxslt/libxslt1-dev@1.1.35-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › libxslt/libxslt1.1@1.1.35-1+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxslt package and not the libxslt package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A use-after-free vulnerability was found in libxslt while parsing xsl nodes that may lead to the dereference of expired pointers and application crash.

Remediation

There is no fixed version for Debian:12 libxslt.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. In version 3.3.2, applications trust unvalidated dataWindow size values from file headers, which can lead to excessive memory allocation and performance degradation when processing malicious files. This is fixed in version 3.3.3.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Release of Invalid Pointer or Reference

  • Vulnerable module: patch
  • Introduced through: patch@2.7.6-7

Detailed paths

  • Introduced through: buildpack-deps@bookworm › patch@2.7.6-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream patch package and not the patch package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An Invalid Pointer vulnerability exists in GNU patch 2.7 via the another_hunk function, which causes a Denial of Service.

Remediation

There is no fixed version for Debian:12 patch.

References

low severity

CVE-2026-0864

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In SQLite 3.49.0 before 3.49.1, certain argument values to sqlite3_db_config (in the C-language API) can cause a denial of service (application crash). An sz*nBig multiplication is not cast to a 64-bit integer, and consequently some memory allocations may be incorrect.

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

Unrestricted Upload of File with Dangerous Type

  • Vulnerable module: tar
  • Introduced through: tar@1.34+dfsg-1.2+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tar@1.34+dfsg-1.2+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream tar package and not the tar package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in tar. A remote attacker could exploit this vulnerability by crafting a malicious archive, leading to hidden file injection with fully attacker-controlled content. This bypasses pre-extraction inspection mechanisms, potentially allowing an attacker to introduce malicious files onto a system without detection.

Remediation

There is no fixed version for Debian:12 tar.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libtiff up to v4.7.1 was discovered to contain a NULL pointer dereference via the component libtiff/tif_open.c.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Out-of-bounds Write

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A heap-buffer-overflow vulnerability was found in LibTIFF, in extractImageSection() at tools/tiffcrop.c:7916 and tools/tiffcrop.c:7801. This flaw allows attackers to cause a denial of service via a crafted tiff file.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Information Exposure

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in the util-linux chfn and chsh utilities when compiled with Readline support. The Readline library uses an "INPUTRC" environment variable to get a path to the library config file. When the library cannot parse the specified file, it prints an error message containing data from the file. This flaw allows an unprivileged user to read root-owned files, potentially leading to privilege escalation. This flaw affects util-linux versions prior to 2.37.4.

Remediation

There is no fixed version for Debian:12 util-linux.

References

low severity

Improper Validation of Specified Quantity in Input

  • Vulnerable module: zlib/zlib1g
  • Introduced through: zlib/zlib1g@1:1.2.13.dfsg-1 and zlib/zlib1g-dev@1:1.2.13.dfsg-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › zlib/zlib1g@1:1.2.13.dfsg-1
  • Introduced through: buildpack-deps@bookworm › zlib/zlib1g-dev@1:1.2.13.dfsg-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream zlib package and not the zlib package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

zlib before 1.3.2 allows CPU consumption via crc32_combine64 and crc32_combine_gen64 because x2nmodp can do right shifts within a loop that has no termination condition.

Remediation

There is no fixed version for Debian:12 zlib.

References

low severity

HTTP Request Smuggling

  • Vulnerable module: nghttp2/libnghttp2-14
  • Introduced through: nghttp2/libnghttp2-14@1.52.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › nghttp2/libnghttp2-14@1.52.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream nghttp2 package and not the nghttp2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers while passing Content-Length verbatim. A backend that resolves the resulting ambiguous message in the attacker's favor enables HTTP request/response smuggling and cross-client response-queue poisoning.

Remediation

There is no fixed version for Debian:12 nghttp2.

References

low severity

Directory Traversal

  • Vulnerable module: patch
  • Introduced through: patch@2.7.6-7

Detailed paths

  • Introduced through: buildpack-deps@bookworm › patch@2.7.6-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream patch package and not the patch package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Directory traversal vulnerability in util.c in GNU patch 2.6.1 and earlier allows user-assisted remote attackers to create or overwrite arbitrary files via a filename that is specified with a .. (dot dot) or full pathname, a related issue to CVE-2010-1679.

Remediation

There is no fixed version for Debian:12 patch.

References

low severity
new

Improper Resource Shutdown or Release

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity
new

Improper Resource Shutdown or Release

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity
new

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability has been found in GNU Binutils 2.43 and classified as problematic. Affected by this vulnerability is the function __sanitizer::internal_strlen of the file binutils/nm.c of the component nm. The manipulation of the argument const leads to buffer overflow. The attack can be launched remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Read

  • Vulnerable module: gdk-pixbuf/gir1.2-gdkpixbuf-2.0
  • Introduced through: gdk-pixbuf/gir1.2-gdkpixbuf-2.0@2.42.10+dfsg-1+deb12u4, gdk-pixbuf/libgdk-pixbuf-2.0-0@2.42.10+dfsg-1+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/gir1.2-gdkpixbuf-2.0@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf-2.0-0@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf-2.0-dev@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf2.0-bin@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf2.0-common@2.42.10+dfsg-1+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream gdk-pixbuf package and not the gdk-pixbuf package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds read can occur due to improper bounds checking against the actual palette size. This vulnerability causes heap bytes to be interpreted as valid palette indices and rendered as RGB pixel values in the output image, allowing an attacker to extract heap content via the generated output, such as a thumbnail.

Remediation

There is no fixed version for Debian:12 gdk-pixbuf.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A denial-of-service and resource exhaustion vulnerability exists within the GDBus component of GLib. The gdbusauth authentication mechanism fails to enforce proper length limitations on data lines read from a client. An unauthenticated local or remote attacker can exploit this lack of input validation by sending excessively long streams of data, causing the application to consume massive amounts of system memory and CPU, potentially leading to a crash or system hang.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Cryptographic Issues

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GLib 2.31.8 and earlier, when the g_str_hash function is used, computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. NOTE: this issue may be disputed by the vendor; the existence of the g_str_hash function is not a vulnerability in the library, because callers of g_hash_table_new and g_hash_table_new_full can specify an arbitrary hash function that is appropriate for the application.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity
new

Link Following

  • Vulnerable module: glib2.0/libglib2.0-0
  • Introduced through: glib2.0/libglib2.0-0@2.74.6-2+deb12u9, glib2.0/libglib2.0-bin@2.74.6-2+deb12u9 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-0@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-bin@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-data@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev@2.74.6-2+deb12u9
  • Introduced through: buildpack-deps@bookworm › glib2.0/libglib2.0-dev-bin@2.74.6-2+deb12u9

NVD Description

Note: Versions mentioned in the description apply only to the upstream glib2.0 package and not the glib2.0 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GLib2. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION and creating the .goutputstream-XXXXXX temporary file fails, the library unlinks the destination and recreates it without exclusive creation or symlink protection. A local attacker who can write to the destination directory can win that race and redirect the write to another file.

Remediation

There is no fixed version for Debian:12 glib2.0.

References

low severity

Information Exposure

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. NOTE: Upstream comments indicate "this is being treated as a non-security bug and no real threat.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

Use of Insufficiently Random Values

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may guess the heap addresses of pthread_created thread. The component is: glibc. NOTE: the vendor's position is "ASLR bypass itself is not a vulnerability.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

Reliance on Undefined

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Resource Management Errors

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Out-of-Bounds

  • Vulnerable module: libpng1.6/libpng-dev
  • Introduced through: libpng1.6/libpng-dev@1.6.39-2+deb12u5 and libpng1.6/libpng16-16@1.6.39-2+deb12u5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng-dev@1.6.39-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng16-16@1.6.39-2+deb12u5

NVD Description

Note: Versions mentioned in the description apply only to the upstream libpng1.6 package and not the libpng1.6 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw has been found in pnggroup libpng up to 1.6.55. Affected by this vulnerability is the function do_pnm2png of the file contrib/pngminus/pnm2png.c of the component pnm2png. This manipulation of the argument width/height causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Remediation

There is no fixed version for Debian:12 libpng1.6.

References

low severity

Resource Management Errors

  • Vulnerable module: libwmf/libwmf-0.2-7
  • Introduced through: libwmf/libwmf-0.2-7@0.2.12-5.1, libwmf/libwmf-dev@0.2.12-5.1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libwmf/libwmf-0.2-7@0.2.12-5.1
  • Introduced through: buildpack-deps@bookworm › libwmf/libwmf-dev@0.2.12-5.1
  • Introduced through: buildpack-deps@bookworm › libwmf/libwmflite-0.2-7@0.2.12-5.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libwmf package and not the libwmf package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The (a) imagearc and (b) imagefilledarc functions in GD Graphics Library (libgd) before 2.0.35 allow attackers to cause a denial of service (CPU consumption) via a large (1) start or (2) end angle degree value.

Remediation

There is no fixed version for Debian:12 libwmf.

References

low severity

Use of Insufficiently Random Values

  • Vulnerable module: libxslt/libxslt1-dev
  • Introduced through: libxslt/libxslt1-dev@1.1.35-1+deb12u4 and libxslt/libxslt1.1@1.1.35-1+deb12u4

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxslt/libxslt1-dev@1.1.35-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › libxslt/libxslt1.1@1.1.35-1+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxslt package and not the libxslt package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libxslt 1.1.29 and earlier, the EXSLT math.random function was not initialized with a random seed during startup, which could cause usage of this function to produce predictable outputs.

Remediation

There is no fixed version for Debian:12 libxslt.

References

low severity

CVE-2016-20012

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combination could be valid for a login session. NOTE: the vendor does not recognize user enumeration as a vulnerability for this product

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Improper Authentication

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenSSH 4.6 and earlier, when ChallengeResponseAuthentication is enabled, allows remote attackers to determine the existence of user accounts by attempting to authenticate via S/KEY, which displays a different response if the user account exists, a similar issue to CVE-2001-1483.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Information Exposure

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Remotely observable behaviour in auth-gss2.c in OpenSSH through 7.8 could be used by remote attackers to detect existence of users on a target system when GSS2 is in use. NOTE: the discoverer states 'We understand that the OpenSSH developers do not want to treat such a username enumeration (or "oracle") as a vulnerability.'

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Improper Validation of Integrity Check Value

  • Vulnerable module: systemd/libsystemd0
  • Introduced through: systemd/libsystemd0@252.39-1~deb12u2 and systemd/libudev1@252.39-1~deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › systemd/libsystemd0@252.39-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › systemd/libudev1@252.39-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream systemd package and not the systemd package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

Remediation

There is no fixed version for Debian:12 systemd.

References

low severity

Improper Validation of Integrity Check Value

  • Vulnerable module: systemd/libsystemd0
  • Introduced through: systemd/libsystemd0@252.39-1~deb12u2 and systemd/libudev1@252.39-1~deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › systemd/libsystemd0@252.39-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › systemd/libudev1@252.39-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream systemd package and not the systemd package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

Remediation

There is no fixed version for Debian:12 systemd.

References

low severity

Improper Validation of Integrity Check Value

  • Vulnerable module: systemd/libsystemd0
  • Introduced through: systemd/libsystemd0@252.39-1~deb12u2 and systemd/libudev1@252.39-1~deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › systemd/libsystemd0@252.39-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › systemd/libudev1@252.39-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream systemd package and not the systemd package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in systemd 253. An attacker can modify the contents of past events in a sealed log file and then adjust the file such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."

Remediation

There is no fixed version for Debian:12 systemd.

References

low severity

Out-of-Bounds

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was determined in LibTIFF up to 4.5.1. Affected by this issue is the function readSeparateStripsetoBuffer of the file tools/tiffcrop.c of the component tiffcrop. The manipulation leads to stack-based buffer overflow. Local access is required to approach this attack. The patch is identified as 8a7a48d7a645992ca83062b3a1873c951661e2b3. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: wget
  • Introduced through: wget@1.21.3-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › wget@1.21.3-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream wget package and not the wget package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.

Remediation

There is no fixed version for Debian:12 wget.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in binutils, specifically within the readelf utility. This vulnerability allows a local attacker to cause a Denial of Service (DoS) by tricking a user into processing a specially crafted Executable and Linkable Format (ELF) file. The exploitation of this flaw can lead to the system becoming unresponsive due to excessive resource consumption or a program crash.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as critical was found in GNU Binutils 2.43. This vulnerability affects the function _bfd_elf_gc_mark_rsec of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 931494c9a89558acb36a03a340c01726545eef24. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.43 and classified as critical. This issue affects the function _bfd_elf_gc_mark_rsec of the file elflink.c of the component ld. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The patch is named f9978defb6fab0bd8583942d97c112b0932ac814. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability, which was classified as critical, was found in GNU Binutils 2.43. Affected is the function bfd_elf_reloc_symbol_deleted_p of the file bfd/elflink.c of the component ld. The manipulation leads to memory corruption. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The patch is identified as b425859021d17adf62f06fb904797cf8642986ad. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Improper Input Validation

  • Vulnerable module: git
  • Introduced through: git@1:2.39.5-0+deb12u3 and git/git-man@1:2.39.5-0+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › git@1:2.39.5-0+deb12u3
  • Introduced through: buildpack-deps@bookworm › git/git-man@1:2.39.5-0+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream git package and not the git package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GIT version 2.15.1 and earlier contains a Input Validation Error vulnerability in Client that can result in problems including messing up terminal configuration to RCE. This attack appear to be exploitable via The user must interact with a malicious git server, (or have their traffic modified in a MITM attack).

Remediation

There is no fixed version for Debian:12 git.

References

low severity

Integer Underflow

  • Vulnerable module: krb5/krb5-multidev
  • Introduced through: krb5/krb5-multidev@1.20.1-2+deb12u5, krb5/libgssapi-krb5-2@1.20.1-2+deb12u5 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › krb5/krb5-multidev@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libgssapi-krb5-2@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libgssrpc4@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libk5crypto3@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkadm5clnt-mit12@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkadm5srv-mit12@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkdb5-10@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5-3@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5-dev@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5support0@1.20.1-2+deb12u5

NVD Description

Note: Versions mentioned in the description apply only to the upstream krb5 package and not the krb5 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2) without a prior bounds check. When bv_len is 0 or 1, the subtraction wraps to a large value which is then truncated to uint16_t, yielding 0xFFFE (65534) or 0xFFFF (65535). The subsequent malloc succeeds and memcpy reads up to 65534 bytes from a 0-1 byte buffer, resulting in a heap out-of-bounds read. The attack vector involves a malicious or compromised LDAP KDB backend returning a krbExtraData attribute with bv_len < 2, triggering the underflow when the KDC or kadmind reads principal data.

Remediation

There is no fixed version for Debian:12 krb5.

References

low severity

Double Free

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libtiff up to v4.7.1 was discovered to contain a double free via the component tools/tiffcrop.c.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Race Condition

  • Vulnerable module: coreutils
  • Introduced through: coreutils@9.1-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › coreutils@9.1-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream coreutils package and not the coreutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In GNU Coreutils through 8.29, chown-core.c in chown and chgrp does not prevent replacement of a plain file with a symlink during use of the POSIX "-R -L" options, which allows local users to modify the ownership of arbitrary files by leveraging a race condition.

Remediation

There is no fixed version for Debian:12 coreutils.

References

low severity

Improper Resource Shutdown or Release

  • Vulnerable module: elfutils/libelf1
  • Introduced through: elfutils/libelf1@0.188-2.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › elfutils/libelf1@0.188-2.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream elfutils package and not the elfutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as problematic was found in GNU elfutils 0.192. This vulnerability affects the function elf_strptr in the library /libelf/elf_strptr.c of the component eu-strip. The manipulation leads to denial of service. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is b16f441cca0a4841050e3215a9f120a6d8aea918. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 elfutils.

References

low severity

Out-of-bounds Write

  • Vulnerable module: gdk-pixbuf/gir1.2-gdkpixbuf-2.0
  • Introduced through: gdk-pixbuf/gir1.2-gdkpixbuf-2.0@2.42.10+dfsg-1+deb12u4, gdk-pixbuf/libgdk-pixbuf-2.0-0@2.42.10+dfsg-1+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/gir1.2-gdkpixbuf-2.0@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf-2.0-0@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf-2.0-dev@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf2.0-bin@2.42.10+dfsg-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › gdk-pixbuf/libgdk-pixbuf2.0-common@2.42.10+dfsg-1+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream gdk-pixbuf package and not the gdk-pixbuf package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an error during ICC profile parsing can leave stale size metadata after the profile buffer is freed. A subsequent allocation in the same decode can cause an out-of-bounds write, potentially crashing the application. To exploit this flaw, an application using gdk-pixbuf must process the malicious JPEG image.

Affected version >= 2.26.4

Remediation

There is no fixed version for Debian:12 gdk-pixbuf.

References

low severity

CVE-2025-30258

  • Vulnerable module: gnupg2/dirmngr
  • Introduced through: gnupg2/dirmngr@2.2.40-1.1+deb12u2, gnupg2/gnupg@2.2.40-1.1+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gnupg2/dirmngr@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg-l10n@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg-utils@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-agent@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-wks-client@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-wks-server@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgconf@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgsm@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgv@2.2.40-1.1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream gnupg2 package and not the gnupg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In GnuPG before 2.5.5, if a user chooses to import a certificate with certain crafted subkey data that lacks a valid backsig or that has incorrect usage flags, the user loses the ability to verify signatures made from certain other signing keys, aka a "verification DoS."

Remediation

There is no fixed version for Debian:12 gnupg2.

References

low severity

Improper Verification of Cryptographic Signature

  • Vulnerable module: gnupg2/dirmngr
  • Introduced through: gnupg2/dirmngr@2.2.40-1.1+deb12u2, gnupg2/gnupg@2.2.40-1.1+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gnupg2/dirmngr@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg-l10n@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg-utils@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-agent@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-wks-client@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-wks-server@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgconf@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgsm@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgv@2.2.40-1.1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream gnupg2 package and not the gnupg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In GnuPG through 2.4.8, if a signed message has \f at the end of a plaintext line, an adversary can construct a modified message that places additional text after the signed material, such that signature verification of the modified message succeeds (although an "invalid armor" message is printed during verification). This is related to use of \f as a marker to denote truncation of a long plaintext line.

Remediation

There is no fixed version for Debian:12 gnupg2.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Improper Initialization

  • Vulnerable module: openldap/libldap-2.5-0
  • Introduced through: openldap/libldap-2.5-0@2.5.13+dfsg-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openldap/libldap-2.5-0@2.5.13+dfsg-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openldap package and not the openldap package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

slapd in OpenLDAP 2.4.45 and earlier creates a PID file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for PID file modification before a root script executes a "kill cat /pathname" command, as demonstrated by openldap-initscript.

Remediation

There is no fixed version for Debian:12 openldap.

References

low severity

Insecure Storage of Sensitive Information

  • Vulnerable module: pam/libpam-modules
  • Introduced through: pam/libpam-modules@1.5.2-6+deb12u2, pam/libpam-modules-bin@1.5.2-6+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › pam/libpam-modules@1.5.2-6+deb12u2
  • Introduced through: buildpack-deps@bookworm › pam/libpam-modules-bin@1.5.2-6+deb12u2
  • Introduced through: buildpack-deps@bookworm › pam/libpam-runtime@1.5.2-6+deb12u2
  • Introduced through: buildpack-deps@bookworm › pam/libpam0g@1.5.2-6+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream pam package and not the pam package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in PAM. The secret information is stored in memory, where the attacker can trigger the victim program to execute by sending characters to its standard input (stdin). As this occurs, the attacker can train the branch predictor to execute an ROP chain speculatively. This flaw could result in leaked passwords, such as those found in /etc/shadow while performing authentications.

Remediation

There is no fixed version for Debian:12 pam.

References

low severity
new

Improper Resource Shutdown or Release

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A weakness has been identified in GNU Binutils 2.47. Affected is the function bfd_putl64 of the file bfd/libbfd.c of the component ld. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Stack-based Buffer Overflow

  • Vulnerable module: coreutils
  • Introduced through: coreutils@9.1-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › coreutils@9.1-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream coreutils package and not the coreutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GNU Coreutils. The sort utility's begfield() function is vulnerable to a heap buffer under-read. The program may access memory outside the allocated buffer if a user runs a crafted command using the traditional key format. A malicious input could lead to a crash or leak sensitive data.

Remediation

There is no fixed version for Debian:12 coreutils.

References

low severity

Link Following

  • Vulnerable module: systemd/libsystemd0
  • Introduced through: systemd/libsystemd0@252.39-1~deb12u2 and systemd/libudev1@252.39-1~deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › systemd/libsystemd0@252.39-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › systemd/libudev1@252.39-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream systemd package and not the systemd package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

systemd, when updating file permissions, allows local users to change the permissions and SELinux security contexts for arbitrary files via a symlink attack on unspecified files.

Remediation

There is no fixed version for Debian:12 systemd.

References

low severity

Link Following

  • Vulnerable module: tar
  • Introduced through: tar@1.34+dfsg-1.2+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tar@1.34+dfsg-1.2+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream tar package and not the tar package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

Remediation

There is no fixed version for Debian:12 tar.

References

low severity

Time-of-check Time-of-use (TOCTOU)

  • Vulnerable module: tar
  • Introduced through: tar@1.34+dfsg-1.2+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tar@1.34+dfsg-1.2+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream tar package and not the tar package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue.

Remediation

There is no fixed version for Debian:12 tar.

References

low severity

Resource Management Errors

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The glob implementation in the GNU C Library (aka glibc or libc6) allows remote authenticated users to cause a denial of service (CPU and memory consumption) via crafted glob expressions that do not match any pathnames, as demonstrated by glob expressions in STAT commands to an FTP daemon, a different vulnerability than CVE-2010-2632.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

Improper Input Validation

  • Vulnerable module: gnutls28/libgnutls30
  • Introduced through: gnutls28/libgnutls30@3.7.9-2+deb12u7

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gnutls28/libgnutls30@3.7.9-2+deb12u7

NVD Description

Note: Versions mentioned in the description apply only to the upstream gnutls28 package and not the gnutls28 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The SSL protocol, as used in certain configurations in Microsoft Windows and Microsoft Internet Explorer, Mozilla Firefox, Google Chrome, Opera, and other products, encrypts data by using CBC mode with chained initialization vectors, which allows man-in-the-middle attackers to obtain plaintext HTTP headers via a blockwise chosen-boundary attack (BCBA) on an HTTPS session, in conjunction with JavaScript code that uses (1) the HTML5 WebSocket API, (2) the Java URLConnection API, or (3) the Silverlight WebClient API, aka a "BEAST" attack.

Remediation

There is no fixed version for Debian:12 gnutls28.

References

low severity

Numeric Errors

  • Vulnerable module: libwmf/libwmf-0.2-7
  • Introduced through: libwmf/libwmf-0.2-7@0.2.12-5.1, libwmf/libwmf-dev@0.2.12-5.1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libwmf/libwmf-0.2-7@0.2.12-5.1
  • Introduced through: buildpack-deps@bookworm › libwmf/libwmf-dev@0.2.12-5.1
  • Introduced through: buildpack-deps@bookworm › libwmf/libwmflite-0.2-7@0.2.12-5.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libwmf package and not the libwmf package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.

Remediation

There is no fixed version for Debian:12 libwmf.

References

low severity

Information Exposure

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenSSH, when using OPIE (One-Time Passwords in Everything) for PAM, allows remote attackers to determine the existence of certain user accounts, which displays a different response if the user account exists and is configured to use one-time passwords (OTP), a similar issue to CVE-2007-2243.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Memory Leak

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A Memory Leak vulnerability exists in SQLite Project SQLite3 3.35.1 and 3.37.0 via maliciously crafted SQL Queries (made via editing the Database File), it is possible to query a record, and leak subsequent bytes of memory that extend beyond the record, which could let a malicious user obtain sensitive information. NOTE: The developer disputes this as a vulnerability stating that If you give SQLite a corrupted database file and submit a query against the database, it might read parts of the database that you did not intend or expect.

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

Improper Certificate Validation

  • Vulnerable module: openldap/libldap-2.5-0
  • Introduced through: openldap/libldap-2.5-0@2.5.13+dfsg-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openldap/libldap-2.5-0@2.5.13+dfsg-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openldap package and not the openldap package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libldap in certain third-party OpenLDAP packages has a certificate-validation flaw when the third-party package is asserting RFC6125 support. It considers CN even when there is a non-matching subjectAltName (SAN). This is fixed in, for example, openldap-2.4.46-10.el8 in Red Hat Enterprise Linux.

Remediation

There is no fixed version for Debian:12 openldap.

References

low severity
new

Out-of-bounds Write

  • Vulnerable module: dash
  • Introduced through: dash@0.5.12-2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › dash@0.5.12-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream dash package and not the dash package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the multi-byte token can need five or six bytes. A local user who can supply such an escape to dash printf or echo %b, including through dash -c and a positional argument, can write one or two bytes past that reservation.

Remediation

There is no fixed version for Debian:12 dash.

References

low severity

Improper Verification of Cryptographic Signature

  • Vulnerable module: apt
  • Introduced through: apt@2.6.1 and apt/libapt-pkg6.0@2.6.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › apt@2.6.1
  • Introduced through: buildpack-deps@bookworm › apt/libapt-pkg6.0@2.6.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream apt package and not the apt package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.

Remediation

There is no fixed version for Debian:12 apt.

References

low severity

Memory Leak

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity
new

Divide By Zero

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for ticks per second in the image being encoded causes a divide-by-zero and crashes the encoder, resulting in a denial of service. The issue is fixed in 7.1.2-31 and 6.9.13-56.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity
new

Resource Exhaustion

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-31 contains a policy bypass vulnerability in the UHDR encoder that fails to perform policy checks during buffer allocation for image pixels. Attackers can bypass resource policies by processing specially crafted UHDR images, potentially causing denial of service through excessive memory allocation.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity
new

Use of Uninitialized Resource

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick versions before 7.1.2-32 and 6.9.13-57 contain uninitialized heap memory disclosure in the GIF decoder's application extension handler in coders/gif.c. Attackers can craft malicious GIF files that cause the number parser to read uninitialized heap memory and store contents as image metadata, disclosing sensitive heap information.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Out-of-bounds Read

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic Security Service Application Programming Interface) indicators when a trailing NULL termination is missing in the auth-indicators array. A remote attacker, under specific configurations involving GSSAPI authentication and a Kerberos environment, could exploit this to cause the SSH authentication path to crash or abort. This leads to a denial of service (DoS), impacting the availability of the SSH service.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity
new

Improper Resource Shutdown or Release

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of the file bfd/elf-eh-frame.c of the component Eh Frame Handler. Performing a manipulation results in null pointer dereference. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity
new

Improper Resource Shutdown or Release

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file bfd/elflink.c. Executing a manipulation can lead to null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a bug report but has not responded yet.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity
new

Improper Resource Shutdown or Release

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_index of the file bfd/elf64-x86-64.c of the component ELF Section Handler. The manipulation leads to null pointer dereference. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. Upgrading to version 2.48 is able to address this issue. The identifier of the patch is 7322e9bc30cb282575a701c307851fd3d66fee68. It is suggested to upgrade the affected component.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity
new

Improper Resource Shutdown or Release

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynrelocs of the file bfd/elfxx-x86.c of the component Dynamic Relocation Allocation. The manipulation results in null pointer dereference. The attack requires a local approach. The exploit is now public and may be used. Upgrading to version 2.48 addresses this issue. The patch is identified as d1268210b6f6/471130b39c0/283d3198bed/0a84e560216/a692a633d40. Upgrading the affected component is recommended.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Memory Leak

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. Attacking locally is a requirement. The identifier of the patch is e51fdff7d2e538c0e5accdd65649ac68e6e0ddd4. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Write

  • Vulnerable module: gnupg2/dirmngr
  • Introduced through: gnupg2/dirmngr@2.2.40-1.1+deb12u2, gnupg2/gnupg@2.2.40-1.1+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gnupg2/dirmngr@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg-l10n@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg-utils@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-agent@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-wks-client@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-wks-server@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgconf@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgsm@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgv@2.2.40-1.1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream gnupg2 package and not the gnupg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GnuPG can be made to spin on a relatively small input by (for example) crafting a public key with thousands of signatures attached, compressed down to just a few KB.

Remediation

There is no fixed version for Debian:12 gnupg2.

References

low severity

Memory Leak

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to consume system resources.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity
new

Resource Exhaustion

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CUBE and HALD) coder: when a specific command line option is supplied, the decoder does not check a configured resource limit, which can result in extra memory allocation. A local user able to pass command line options to ImageMagick can therefore exceed the intended memory policy limit, causing a limited availability impact. The issue is fixed in 7.1.2-31 and 6.9.13-56.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Out-of-Bounds

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was determined in strukturag libheif up to 1.21.2. This affects the function vvdec_push_data2 of the file libheif/plugins/decoder_vvdec.cc of the component HEIF File Parser. Executing a manipulation of the argument size can lead to out-of-bounds read. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. This patch is called b97c8b5f198b27f375127cd597a35f2113544d03. It is advisable to implement a patch to correct this issue.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Unchecked Return Value

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., it does not calculate a string length after NULL checking.

Remediation

There is no fixed version for Debian:12 libxml2.

References

low severity

Out-of-Bounds

  • Vulnerable module: ncurses/libncurses-dev
  • Introduced through: ncurses/libncurses-dev@6.4-4, ncurses/libncurses5-dev@6.4-4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses5-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncurses6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncursesw5-dev@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libncursesw6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/libtinfo6@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/ncurses-base@6.4-4
  • Introduced through: buildpack-deps@bookworm › ncurses/ncurses-bin@6.4-4

NVD Description

Note: Versions mentioned in the description apply only to the upstream ncurses package and not the ncurses package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability has been found in GNU ncurses up to 6.5-20250322 and classified as problematic. This vulnerability affects the function postprocess_termcap of the file tinfo/parse_entry.c. The manipulation leads to stack-based buffer overflow. The attack needs to be approached locally. Upgrading to version 6.5-20250329 is able to address this issue. It is recommended to upgrade the affected component.

Remediation

There is no fixed version for Debian:12 ncurses.

References

low severity

Link Following

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

_is_safe in the File::Temp module for Perl does not properly handle symlinks.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

Out-of-bounds Write

  • Vulnerable module: procps
  • Introduced through: procps@2:4.0.2-3 and procps/libproc2-0@2:4.0.2-3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › procps@2:4.0.2-3
  • Introduced through: buildpack-deps@bookworm › procps/libproc2-0@2:4.0.2-3

NVD Description

Note: Versions mentioned in the description apply only to the upstream procps package and not the procps package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.

Remediation

There is no fixed version for Debian:12 procps.

References

low severity

Incorrect Resource Transfer Between Spheres

  • Vulnerable module: systemd/libsystemd0
  • Introduced through: systemd/libsystemd0@252.39-1~deb12u2 and systemd/libudev1@252.39-1~deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › systemd/libsystemd0@252.39-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › systemd/libudev1@252.39-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream systemd package and not the systemd package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is executed, if ForwardToWall=yes is set.

Remediation

There is no fixed version for Debian:12 systemd.

References

low severity

Out-of-Bounds

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component tiffcrop. Executing manipulation can lead to memory corruption. The attack can only be executed locally. The exploit has been made available to the public and could be exploited.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Out-of-bounds Write

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: unzip
  • Introduced through: unzip@6.0-28+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › unzip@6.0-28+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream unzip package and not the unzip package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Remediation

There is no fixed version for Debian:12 unzip.

References

low severity

Memory Leak

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Memory Leak

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be initiated remotely. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Memory Leak

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Memory Leak

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue. The code maintainer explains: "I'm not going to commit some of the leak fixes I've been working on to the 2.44 branch due to concern that would destabilise ld. All of the reported leaks in this bugzilla have been fixed on binutils master."

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-Bounds

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as problematic has been found in GNU Binutils 2.43. This affects the function _bfd_elf_write_section_eh_frame of the file bfd/elf-eh-frame.c of the component ld. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity
new

NULL Pointer Dereference

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder reaches a memory (resource) limit at a specific point during processing, the failed allocation is not handled and a NULL pointer is dereferenced, which can lead to a denial of service (application crash) when processing a specially crafted or sufficiently large PNM image.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Access of Resource Using Incompatible Type ('Type Confusion')

  • Vulnerable module: libxslt/libxslt1-dev
  • Introduced through: libxslt/libxslt1-dev@1.1.35-1+deb12u4 and libxslt/libxslt1.1@1.1.35-1+deb12u4

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxslt/libxslt1-dev@1.1.35-1+deb12u4
  • Introduced through: buildpack-deps@bookworm › libxslt/libxslt1.1@1.1.35-1+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxslt package and not the libxslt package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML document node as a regular XML element node, resulting in a type confusion. This can cause unexpected memory reads and potential crashes. While difficult to exploit, the flaw could lead to application instability or denial of service.

Remediation

There is no fixed version for Debian:12 libxslt.

References

low severity
new

Use After Free

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity
new

CVE-2026-61081

  • Vulnerable module: mariadb/libmariadb-dev
  • Introduced through: mariadb/libmariadb-dev@1:10.11.18-0+deb12u1, mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb3@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/mariadb-common@1:10.11.18-0+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream mariadb package and not the mariadb package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).

Remediation

There is no fixed version for Debian:12 mariadb.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy unknown encoding handler user data.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity
new

Link Following

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decoder that allows attackers to bypass path policy write restrictions via symlink swaps. An attacker can replace a symlink between policy validation (check-time) and the file write operation (use-time) to write to policy-denied locations.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Improper Resource Shutdown or Release

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in LibTIFF up to 4.7.0. It has been declared as problematic. Affected by this vulnerability is the function t2p_read_tiff_init of the file tools/tiff2pdf.c of the component fax2ps. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The complexity of an attack is rather high. The exploitation appears to be difficult. The patch is named 2ebfffb0e8836bfb1cd7d85c059cd285c59761a4. It is recommended to apply a patch to fix this issue.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Improper Resource Shutdown or Release

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability classified as problematic was found in libtiff 4.6.0. This vulnerability affects the function PS_Lvl2page of the file tools/tiff2ps.c of the component tiff2ps. The manipulation leads to null pointer dereference. It is possible to launch the attack on the local host. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The name of the patch is 6ba36f159fd396ad11bf6b7874554197736ecc8b. It is recommended to apply a patch to fix this issue. One of the maintainers explains, that "[t]his error only occurs if DEFER_STRILE_LOAD (defer-strile-load:BOOL=ON) or TIFFOpen( .. "rD") option is used."

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

Memory Leak

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attack is restricted to local execution. This attack is characterized by high complexity. It is indicated that the exploitability is difficult. The exploit has been published and may be used. There is ongoing doubt regarding the real existence of this vulnerability. This patch is called ed141286a37f6e5ddafb5069347ff5d587e7a4e0. It is best practice to apply a patch to resolve this issue. A researcher disputes the security impact of this issue, because "this is a memory leak on a command line tool that is about to exit anyway". In the reply the project maintainer declares this issue as "a simple 'bug' when leaving the command line tool and (...) not a security issue at all".

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

CVE-2024-53589

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2024-57360

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: nm --without-symbol-version function.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-66861

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in function d_unqualified_name in file cp-demangle.c in BinUtils 2.26 allowing attackers to cause a denial of service via crafted PE file.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-66862

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A buffer overflow vulnerability in function gnu_special in file cplus-dem.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-66863

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in function d_discriminator in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-66865

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in function d_print_comp_inner in file cp-demangle.c in BinUtils 2.26 allows attackers to cause a denial of service via crafted PE file.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-69644

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue was discovered in Binutils before 2.46. The objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed debug information. A logic flaw in the handling of DWARF location list headers can cause objdump to enter an unbounded loop and produce endless output until manually interrupted. This issue affects versions prior to the upstream fix and allows a local attacker to cause excessive resource consumption by supplying a malicious input file.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-69645

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug information. A logic error in the handling of DWARF compilation units can result in an invalid offset_size value being used inside byte_get_little_endian, leading to an abort (SIGABRT). The issue was observed in binutils 2.44. A local attacker can trigger the crash by supplying a malicious input file.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-69646

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Binutils objdump contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF debug_rnglists data. A logic error in the handling of the debug_rnglists header can cause objdump to repeatedly print the same warning message and fail to terminate, resulting in an unbounded logging loop until the process is interrupted. The issue was observed in binutils 2.44. A local attacker can exploit this vulnerability by supplying a malicious input file, leading to excessive CPU and I/O usage and preventing completion of the objdump analysis.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-69647

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF loclists data. A logic flaw in the DWARF parsing code can cause readelf to repeatedly print the same table output without making forward progress, resulting in an unbounded output loop that never terminates unless externally interrupted. A local attacker can trigger this behavior by supplying a malicious input file, causing excessive CPU and I/O usage and preventing readelf from completing its analysis.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-69648

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Binutils thru 2.45.1 readelf contains a denial-of-service vulnerability when processing a crafted binary with malformed DWARF .debug_rnglists data. A logic flaw in the DWARF parsing path causes readelf to repeatedly print the same warning message without making forward progress, resulting in a non-terminating output loop that requires manual interruption. No evidence of memory corruption or code execution was observed.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

CVE-2025-69652

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Binutils thru 2.46 readelf contains a vulnerability that leads to an abort (SIGABRT) when processing a crafted ELF binary with malformed DWARF abbrev or debug information. Due to incomplete state cleanup in process_debug_info(), an invalid debug_info_p state may propagate into DWARF attribute parsing routines. When certain malformed attributes result in an unexpected data length of zero, byte_get_little_endian() triggers a fatal abort. No evidence of memory corruption or code execution was observed; the impact is limited to denial of service.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Write

  • Vulnerable module: binutils
  • Introduced through: binutils@2.40-2, binutils/binutils-common@2.40-2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › binutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-common@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/binutils-x86-64-linux-gnu@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libbinutils@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf-nobfd0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libctf0@2.40-2
  • Introduced through: buildpack-deps@bookworm › binutils/libgprofng0@2.40-2

NVD Description

Note: Versions mentioned in the description apply only to the upstream binutils package and not the binutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is false due to upstream security policy.

Remediation

There is no fixed version for Debian:12 binutils.

References

low severity

Out-of-bounds Write

  • Vulnerable module: bzip2/bzip2
  • Introduced through: bzip2/bzip2@1.0.8-5+b1, bzip2/libbz2-1.0@1.0.8-5+b1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › bzip2/bzip2@1.0.8-5+b1
  • Introduced through: buildpack-deps@bookworm › bzip2/libbz2-1.0@1.0.8-5+b1
  • Introduced through: buildpack-deps@bookworm › bzip2/libbz2-dev@1.0.8-5+b1

NVD Description

Note: Versions mentioned in the description apply only to the upstream bzip2 package and not the bzip2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corruption and a crash (denial of service).

This issue was fixed in bzip2 patch 35d122a3df8b0cc4082a4d89fdc6ee99f375fe67

Remediation

There is no fixed version for Debian:12 bzip2.

References

low severity

Reachable Assertion

  • Vulnerable module: cairo/libcairo-gobject2
  • Introduced through: cairo/libcairo-gobject2@1.16.0-7, cairo/libcairo-script-interpreter2@1.16.0-7 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-gobject2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo-script-interpreter2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2@1.16.0-7
  • Introduced through: buildpack-deps@bookworm › cairo/libcairo2-dev@1.16.0-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream cairo package and not the cairo package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Cairo through 1.18.4, as used in Poppler through 25.08.0, has an "unscaled->face == NULL" assertion failure for _cairo_ft_unscaled_font_fini in cairo-ft-font.c.

Remediation

There is no fixed version for Debian:12 cairo.

References

low severity

Authentication Bypass

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against proxyA using Digest auth, a subsequent transfer routed through proxyB erroneously leaks the Proxy-Authorization: header intended solely for proxyA.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Authentication Bypass

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Successfully using libcurl to do a transfer to a specific HTTP origin (hostA) with Digest authentication and then changing the origin to a different one (hostB) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the Authorization: header field meant for hostA, to hostB.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Buffer Overflow

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When libcurl is asked to perform automatic gzip decompression of content-encoded HTTP responses with the CURLOPT_ACCEPT_ENCODING option, using zlib 1.2.0.3 or older, an attacker-controlled integer overflow would make libcurl perform a buffer overflow.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2025-10966

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host verification mechanisms.

This prevents curl from detecting MITM attackers and more.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2025-14017

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When doing multi-threaded LDAPS transfers (LDAP over TLS) with libcurl, changing TLS options in one thread would inadvertently change them globally and therefore possibly also affect other concurrently setup transfers.

Disabling certificate verification for a specific transfer could unintentionally disable the feature for other threads as well.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2025-15079

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When doing SSH-based transfers using either SCP or SFTP, and setting the known_hosts file, libcurl could still mistakenly accept connecting to hosts not present in the specified file if they were added as recognized in the libssh global known_hosts file.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2025-15224

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When doing SSH-based transfers using either SCP or SFTP, and asked to do public key authentication, curl would wrongly still ask and authenticate using a locally running SSH agent.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity
new

CVE-2026-13608

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An attacker executing a Man-in-the-Middle (MITM) attack can inject a premature or shortcut response that bypasses complete peer validation.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity
new

CVE-2026-18924

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw in libcurl's handling of HTTP/2 Server Push streams, when the parent handle is set to share connections with other handles, can lead to use-after-free in the cleanup process.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2026-1965

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libcurl can in some circumstances reuse the wrong connection when asked to do an Negotiate-authenticated HTTP or HTTPS request.

libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.

When reusing a connection a range of criterion must first be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different credentials. One underlying reason being that Negotiate sometimes authenticates connections and not requests, contrary to how HTTP is designed to work.

An application that allows Negotiate authentication to a server (that responds wanting Negotiate) with user1:password1 and then does another operation to the same server also using Negotiate but with user2:password2 (while the previous connection is still alive) - the second request wrongly reused the same connection and since it then sees that the Negotiate negotiation is already made, it sends the request over that connection thinking it uses the user2 credentials when it is in fact still using the connection authenticated for user1...

The set of authentication methods to use is set with CURLOPT_HTTPAUTH.

Applications can disable libcurl's reuse of connections and thus mitigate this problem, by using one of the following libcurl options to alter how connections are or are not reused: CURLOPT_FRESH_CONNECT, CURLOPT_MAXCONNECTS and CURLMOPT_MAX_HOST_CONNECTIONS (if using the curl_multi API).

Remediation

There is no fixed version for Debian:12 curl.

References

low severity
new

CVE-2026-19931

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credentials. This can make user B's request get sent over user A's previously authenticated connection.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2026-6429

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When asked to both use a .netrc file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity
new

CVE-2026-80230

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When CURLOPT_PINNEDPUBLICKEY is configured alongside options that disable standard peer verification (CURLOPT_SSL_VERIFYPEER = 0 and CURLOPT_SSL_VERIFYHOST = 0), libcurl fails to enforce public key pinning on connections established without a presented server certificate. Bypassing the pinning check under these disabled-verification conditions allows unauthenticated connections to succeed when they should be rejected.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity
new

CVE-2026-82209

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When libpsl support is enabled, libcurl fails to enforce the Public Suffix List boundary check when processing a Set-Cookie header where the Domain attribute explicitly matches an origin host that is itself a public suffix (e.g., Domain=co.uk set by co.uk).

Instead of coercing it into a strict host-only cookie, libcurl saves the cookie with wildcard domain scope (.co.uk). Consequently, the cookie is inappropriately included in subsequent outbound requests or HTTP redirects to arbitrary sibling subdomains under the same public suffix (e.g., attacker.co.uk).

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2026-8458

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libcurl might in some circumstances reuse the wrong connection when asked to do Negotiate-authenticated ones, even when they are set to use different "services".

libcurl features a pool of recent connections so that subsequent requests can reuse an existing connection to avoid overhead.

When reusing a connection a range of criteria must be met. Due to a logical error in the code, a request that was issued by an application could wrongfully reuse an existing connection to the same server that was authenticated using different services.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2026-8924

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set "super cookies" that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2026-8932

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse.

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

CVE-2026-9547

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When a libcurl-based application performs transfers via SCP:// or SFTP:// and utilizes the CURLOPT_SSH_KEYFUNCTION callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the known_hosts file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Improper Certificate Validation

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability exists where a connection requiring TLS incorrectly reuses an existing unencrypted connection from the same connection pool. If an initial transfer is made in clear-text (via IMAP, SMTP, or POP3), a subsequent request to that same host bypasses the TLS requirement and instead transmit data unencrypted.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Improper Certificate Validation

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When a user invokes curl using a schemeless URL combined with --proto-default sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Improper Certificate Validation

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Improper Certificate Validation

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libcurl skips the certificate verification for a QUIC connection under certain conditions, when built to use wolfSSL. If told to use an unknown/bad cipher or curve, the error path accidentally skips the verification and returns OK, thus ignoring any certificate problems.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Insufficiently Protected Credentials

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

curl might erroneously pass on credentials for a first proxy to a second proxy.

This can happen when the following conditions are true:

  1. curl is setup to use specific different proxies for different URL schemes
  2. the first proxy needs credentials
  3. the second proxy uses no credentials
  4. while using the first proxy (using say http://), curl is asked to follow a redirect to a URL using another scheme (say https://), accessed using a second, different, proxy

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Use After Free

  • Vulnerable module: curl
  • Introduced through: curl@7.88.1-10+deb12u15, curl/libcurl3-gnutls@7.88.1-10+deb12u15 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › curl@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl3-gnutls@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4@7.88.1-10+deb12u15
  • Introduced through: buildpack-deps@bookworm › curl/libcurl4-openssl-dev@7.88.1-10+deb12u15

NVD Description

Note: Versions mentioned in the description apply only to the upstream curl package and not the curl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via CURLOPT_STREAM_DEPENDS or CURLOPT_STREAM_DEPENDS_E, subsequently invokes curl_easy_reset(), and finally terminates the handle with curl_easy_cleanup(). During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.

Remediation

There is no fixed version for Debian:12 curl.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: diffutils
  • Introduced through: diffutils@1:3.8-4

Detailed paths

  • Introduced through: buildpack-deps@bookworm › diffutils@1:3.8-4

NVD Description

Note: Versions mentioned in the description apply only to the upstream diffutils package and not the diffutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

diff3 tool from GNU diffutils is vulnerable to a heap‑based buffer overflow due to multiple signed integer overflows in line‑mapping calculations. Incorrect arithmetic in mapping line ranges can result in corrupted values being used for memory allocation and loop bounds. When processing crafted diff output, these overflows may cause the application to allocate insufficient memory and subsequently perform out‑of‑bounds writes during internal processing.  An attacker who can control the output of the diff program used by diff3 (e.g. via --diff-program pointing to a malicious script) can trigger out-of-bounds writes, resulting in a crash and potentially remote code execution depending on the environment.

This issue has been fixed in commit 9ff04d5b84743e331e80b589335a52c5480d1815 

NOTE: The project maintainers claim that this is not a security issue. They state that the worst outcome this issue can cause is a crash of diff and that it cannot be used to escalate privileges.

Remediation

There is no fixed version for Debian:12 diffutils.

References

low severity

CVE-2024-25260

  • Vulnerable module: elfutils/libelf1
  • Introduced through: elfutils/libelf1@0.188-2.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › elfutils/libelf1@0.188-2.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream elfutils package and not the elfutils package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.

Remediation

There is no fixed version for Debian:12 elfutils.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libexpat in Expat before 2.7.2 allows attackers to trigger large dynamic memory allocations via a small document that is submitted for parsing.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Incorrect Synchronization

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In libexpat before 2.8.2, there is a heap-based buffer overflow in doProlog in xmlparse.c because scaffold backing array reallocation is mishandled when there is data-structure sharing across parsers.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

Insufficient Entropy

  • Vulnerable module: expat/libexpat1
  • Introduced through: expat/libexpat1@2.5.0-1+deb12u3 and expat/libexpat1-dev@2.5.0-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › expat/libexpat1@2.5.0-1+deb12u3
  • Introduced through: buildpack-deps@bookworm › expat/libexpat1-dev@2.5.0-1+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream expat package and not the expat package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libexpat before 2.8.0 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.

Remediation

There is no fixed version for Debian:12 expat.

References

low severity

CVE-2026-18374

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Passing an effectively empty string to the ,ccs= syntax extension of the mode argument in the fopen function in the GNU C Library version 2.45 or earlier may result in a heap buffer overflow when the mode string input to the function is attacker controlled.

This usage pattern is not seen in applications in common GNU/Linux distributions and applications that process user-supplied values for ccs should not pass them through without validation.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-19499

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied output buffer when a conversion uses right-justified width padding.

Exploitation requires an application code path that calls strfmon or strfmon_l with right-justified width padding into a destination buffer that is large enough for the padding to succeed but too small for the internal memmove call. The field width or format may be attacker-influenced or a fixed susceptible pattern in the caller.

At the time of publication, no network-facing application impact is known.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-19542

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Calling tdelete on a sufficiently deep tree in the GNU C Library version 2.1 to 2.44 may write one pointer past the end of an alloca-allocated array on the stack, which may crash the application.

The tdelete implementation keeps an explicit stack of parent nodes for rebalancing, which is grown as needed while descending the tree. Two rebalancing branches push an additional entry without checking the capacity, and write past the array when the stack is exactly full. Triggering this requires a node at a depth of exactly 40 (or 40 plus a multiple of 20), which implies a tree with at least a million nodes, so an attacker must drive a large number of insertions and deletions through an application that uses tsearch and tdelete. The written value is a pointer into a tree node and is not directly attacker controlled. No affected application in common distributions has been identified.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-5435

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-5928

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library version 2.43 or earlier, may result in an attempt to read bytes before an allocated buffer, potentially resulting in unintentional disclosure of neighboring data in the heap, or a program crash.

A bug in the wide character pushback implementation (_IO_wdefault_pbackfail in libio/wgenops.c) causes ungetwc() to operate on the regular character buffer (fp->_IO_read_ptr) instead of the actual wide-stream read pointer (fp->_wide_data->_IO_read_ptr). The program crash may happen in cases where fp->_IO_read_ptr is not initialized and hence points to NULL. The buffer under-read requires a special situation where the input character encoding is such that there are overlaps between single byte representations and multibyte representations in that encoding, resulting in spurious matches. The spurious match case is not possible in the standard Unicode character sets.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-6238

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to validate the RDATA content against the RDATA length in a DNS response when processing LOC, CERT, TKEY or TSIG records, which may allow an attacker to craft a DNS response, causing a target application to crash or read uninitialized memory.

These functions are for application debugging only and hence not in the path of code executed by the DNS resolver. Further, they have been deprecated since version 2.34 and should not be used by any new applications. Applications should consider porting away from these interfaces since they may be removed in future versions.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-6368

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to version 2.43 can cause the interface to return invalid memory in the we_wordv member, which on subsequent calls to wordfree may abort the process.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-6791

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the user's home directory. The implementation allocates memory for this username directly on the stack using the strndupa macro. Because the size of this allocation was determined by the length of the user-supplied input without any bounds checks, passing an excessively long username e.g. thousands of characters, forces the thread to exhaust its stack space. Thus if an application passes untrusted, attacker-controlled input to the wordexp function, an attacker can trigger a stack clash.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-77117

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.

Some SHIFT_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the SHIFT_JISX0213 character set is affected, which is not commonly used. The related defect in the EUC_JISX0213 converter is tracked separately as CVE-2026-80489.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-80489

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the GNU C Library version 2.3 to 2.44 may result in the converter making no progress, causing the calling application to hang.

Some EUC_JISX0213 sequences decode to two code points. If the output buffer has room for only the first one, the converter stores the second in the conversion state and returns E2BIG, but it never clears that pending character after emitting it on the next call. The converter then keeps emitting the pending character without consuming further input, so an application that retries the conversion loops forever. The input must be attacker controlled and the application must convert it with an output buffer small enough to split the two code points. Only the EUC_JISX0213 character set is affected, which is not commonly used. The related defect in SHIFT_JISX0213 converter is tracked separately as CVE-2026-77117.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity
new

CVE-2026-8674

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search list contains a domain of roughly 200 characters or more in the GNU C Library version 2.26 to 2.44 results in an assertion failure which aborts the process.

The resolver truncates the search list when copying it into the fixed-size _res.defdname buffer, then asserts that the copy is consistent with the full configuration. The consistency check compared against the wrong size and did not handle a first entry that does not fit, so a correctly truncated list failed the assertion. Any process that resolves names through the library is affected, including long-running processes that reload /etc/resolv.conf on the next query after it changes. Search domains are commonly written to /etc/resolv.conf from data received over DHCP or from a VPN server, so an attacker on the local network may be able to trigger this without privileges on the target system, subject to validation by the network configuration software.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity
new

CVE-2026-86805

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A time-of-check to time-of-use (TOCTOU) race condition in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to escalate privileges. When expanding $ORIGIN in DT_RPATH for setuid/setgid (AT_SECURE) programs, glibc validates the lexically normalized search path against the trusted directories but then opens the raw, un-normalized path. On systems where the Linux fs.protected_hardlinks sysctl is disabled, a local attacker who hard-links such a program into an attacker-controlled directory and wins a race to replace an intermediate path component with a symbolic link can direct the loader outside the trusted directory, causing it to load an attacker-controlled shared object and execute arbitrary code with the elevated privileges of the program.

Exploitation requires an installed setuid or setgid binary whose DT_RPATH uses $ORIGIN followed by ".." traversal that normalizes into a trusted directory, and the ability to hard-link that binary and win the race by swapping a path component for a symbolic link. Major Linux-based OS distributions ship with fs.protected_hardlinks enabled by default and mitigate the vulnerability.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity
new

CVE-2026-89092

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system.

Exploitation of this bug needs a system that has nscd enabled and using an untrusted DNS server for name resolution, with the compromised DNS server being capable of processing records large enough to result in a stack overflow in an nscd thread stack.  During experimentation, bind 9 was unable to handle large records, but that could change in future or with a different name server.  In typical installations, nscd is executed in an isolated context as its own user without a shell, due to which any compromise of that service is isolated.

There is a remote possibility of nscd cache corruption if an attacker manages to get the stack pointer into a desired point in the heap, potentially resulting in other caches in nscd being overwritten with corrupt data through the stack overflow, until the buggy code path eventually results in a crash.

Finally, a crash in nscd may result in performance degradation when resolving names, but it does not result in a denial of service.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity
new

CVE-2026-95818

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allows a local attacker to crash or corrupt the memory of setuid/setgid (AT_SECURE) programs.

When such a program's DT_RPATH or DT_RUNPATH begins with $ORIGIN and is followed by NUL or '/' the loader both reads past the end of the path buffer and writes past the end of a stack-allocated internal buffer. The corrupted loader stack can lead to a loader crash (denial of service) and limited disclosure of process memory.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity
new

CVE-2026-97399

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The strncasecmp function in the GNU C Library 2.24 and later optimized for the Power8 architecture may read one byte beyond the input size limit, which may crash a program when that byte is not readable.

This condition may happen when the input strings to the strncasecmp function are attacker controlled in an application and they match all the way up to the edge of their page and the neighbouring page is either not mapped or is not readable.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

Out-of-bounds Write

  • Vulnerable module: glibc/libc-bin
  • Introduced through: glibc/libc-bin@2.36-9+deb12u14, glibc/libc-dev-bin@2.36-9+deb12u14 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › glibc/libc-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc-dev-bin@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6@2.36-9+deb12u14
  • Introduced through: buildpack-deps@bookworm › glibc/libc6-dev@2.36-9+deb12u14

NVD Description

Note: Versions mentioned in the description apply only to the upstream glibc package and not the glibc package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library version 2.7 to version 2.43 with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow.

Remediation

There is no fixed version for Debian:12 glibc.

References

low severity

CVE-2026-57062

  • Vulnerable module: gnupg2/dirmngr
  • Introduced through: gnupg2/dirmngr@2.2.40-1.1+deb12u2, gnupg2/gnupg@2.2.40-1.1+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gnupg2/dirmngr@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg-l10n@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gnupg-utils@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-agent@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-wks-client@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpg-wks-server@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgconf@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgsm@2.2.40-1.1+deb12u2
  • Introduced through: buildpack-deps@bookworm › gnupg2/gpgv@2.2.40-1.1+deb12u2

NVD Description

This vulnerability has not been analyzed by NVD yet.

Remediation

There is no fixed version for Debian:12 gnupg2.

References

low severity

Insecure Temporary File

  • Vulnerable module: gzip
  • Introduced through: gzip@1.12-1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › gzip@1.12-1

NVD Description

Note: Versions mentioned in the description apply only to the upstream gzip package and not the gzip package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.

This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269

Remediation

There is no fixed version for Debian:12 gzip.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: harfbuzz/libharfbuzz0b
  • Introduced through: harfbuzz/libharfbuzz0b@6.0.0+dfsg-3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › harfbuzz/libharfbuzz0b@6.0.0+dfsg-3

NVD Description

Note: Versions mentioned in the description apply only to the upstream harfbuzz package and not the harfbuzz package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

HarfBuzz is a text shaping engine. Prior to version 12.3.0, a null pointer dereference vulnerability exists in the SubtableUnicodesCache::create function located in src/hb-ot-cmap-table.hh. The function fails to check if hb_malloc returns NULL before using placement new to construct an object at the returned pointer address. When hb_malloc fails to allocate memory (which can occur in low-memory conditions or when using custom allocators that simulate allocation failures), it returns NULL. The code then attempts to call the constructor on this null pointer using placement new syntax, resulting in undefined behavior and a Segmentation Fault. This issue has been patched in version 12.3.0.

Remediation

There is no fixed version for Debian:12 harfbuzz.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.13-51 and 7.0.1-0 and above prior to 7.1.2-26, an invalid kernel can cause a heap buffer over-write when performing a morphology operation with a user supplied kernel. This issue has been fixed in versions 6.9.13-51 and 7.1.2-26.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Out-of-bounds Read

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

Out-of-bounds Write

  • Vulnerable module: imagemagick
  • Introduced through: imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13, imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › imagemagick@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6-common@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/imagemagick-6.q16@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-arch-config@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-6-extra@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickcore-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6-headers@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-6@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-6.q16-dev@8:6.9.11.60+dfsg-1.6+deb12u13
  • Introduced through: buildpack-deps@bookworm › imagemagick/libmagickwand-dev@8:6.9.11.60+dfsg-1.6+deb12u13

NVD Description

Note: Versions mentioned in the description apply only to the upstream imagemagick package and not the imagemagick package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, a heap buffer over-write can occur in the fx operation by passing a crafted argument. This issue has been fixed in version 7.1.2-27.

Remediation

There is no fixed version for Debian:12 imagemagick.

References

low severity

CVE-2024-26461

  • Vulnerable module: krb5/krb5-multidev
  • Introduced through: krb5/krb5-multidev@1.20.1-2+deb12u5, krb5/libgssapi-krb5-2@1.20.1-2+deb12u5 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › krb5/krb5-multidev@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libgssapi-krb5-2@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libgssrpc4@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libk5crypto3@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkadm5clnt-mit12@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkadm5srv-mit12@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkdb5-10@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5-3@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5-dev@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5support0@1.20.1-2+deb12u5

NVD Description

Note: Versions mentioned in the description apply only to the upstream krb5 package and not the krb5 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/lib/gssapi/krb5/k5sealv3.c.

Remediation

There is no fixed version for Debian:12 krb5.

References

low severity

Memory Leak

  • Vulnerable module: krb5/krb5-multidev
  • Introduced through: krb5/krb5-multidev@1.20.1-2+deb12u5, krb5/libgssapi-krb5-2@1.20.1-2+deb12u5 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › krb5/krb5-multidev@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libgssapi-krb5-2@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libgssrpc4@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libk5crypto3@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkadm5clnt-mit12@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkadm5srv-mit12@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkdb5-10@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5-3@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5-dev@1.20.1-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › krb5/libkrb5support0@1.20.1-2+deb12u5

NVD Description

Note: Versions mentioned in the description apply only to the upstream krb5 package and not the krb5 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Kerberos 5 (aka krb5) 1.21.2 contains a memory leak in /krb5/src/lib/rpc/pmap_rmt.c.

Remediation

There is no fixed version for Debian:12 krb5.

References

low severity

CVE-2025-29070

  • Vulnerable module: lcms2/liblcms2-2
  • Introduced through: lcms2/liblcms2-2@2.14-2+deb12u1 and lcms2/liblcms2-dev@2.14-2+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › lcms2/liblcms2-2@2.14-2+deb12u1
  • Introduced through: buildpack-deps@bookworm › lcms2/liblcms2-dev@2.14-2+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream lcms2 package and not the lcms2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."

Remediation

There is no fixed version for Debian:12 lcms2.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes decoder_context::read_slice_NAL() (libde265/decctx.cc:481) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

CVE-2023-51792

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Buffer Overflow vulnerability in libde265 v1.0.12 allows a local attacker to cause a denial of service via the allocation size exceeding the maximum supported size of 0x10000000000.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

CVE-2024-38949

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to display444as420 function at sdl.cc

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

CVE-2024-38950

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attackers to crash the application via crafted payload to __interceptor_memcpy function.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

CVE-2025-61147

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

strukturag libde265 commit d9fea9d wa discovered to contain a segmentation fault via the component decoder_context::compute_framedrop_table().

Remediation

There is no fixed version for Debian:12 libde265.

References

low severity
new

CVE-2026-88373

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL() is called with a zero-length NAL unit, the resulting NAL_unit may retain a NULL backing buffer, which is subsequently passed as the destination argument to memcpy() in NAL_unit::set_data(). Although the copy length is zero, this violates the nonnull requirement of memcpy() and results in undefined behavior, causing process termination in UBSan-instrumented builds and denial of service.

Remediation

There is no fixed version for Debian:12 libde265.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with large dimensions and 16-bit luma samples to cause an integer overflow, an undersized allocation, and an out-of-bounds heap read that may expose heap data in decoded output or crash the decoder. Version 1.1.1 contains a patch.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow in de265_image_get_buffer() (libde265/image.cc:128). The overflow wraps the plane allocation size to a small value (~1 KB), but the subsequent fill_image() call computes the real size using size_t, writing ~4 GB into the undersized heap buffer. Version 1.1.0 patches the issue.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger an integer overflow and cause out-of-bounds heap reads or writes, potentially disclosing data, corrupting memory, or crashing the decoder. Version 1.1.1 contains a patch.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

Out-of-bounds Read

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, decoder_context::decode_slice_unit_tiles (libde265/decctx.cc:920) reads pps.CtbAddrRStoTS[ctbAddrRS] at line 966 where ctbAddrRS = ctbY * ctbsWidth + ctbX is computed from PPS-supplied colBd[]/rowBd[] arrays without validating the result against CtbAddrRStoTS.size() == sps-&gt;PicSizeInCtbsY. A malformed PPS that passes set_derived_values but encodes geometry inconsistent with the SPS produces a ctbAddrRS past the allocation, causing a 4-byte heap-buffer-overflow READ. Version 1.0.19 fixes the issue.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

Out-of-bounds Read

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in decoder_context::decode_slice_unit_WPP() in libde265/decctx.cc. When decoding a WPP (Wavefront Parallel Processing) HEVC slice, ctbAddrRS is computed as ctbRow * ctbsWidth inside the entry-point loop. If the PPS/SPS headers are crafted so that this value exceeds pps.CtbAddrRStoTS.size(), the subsequent array access pps.CtbAddrRStoTS[ctbAddrRS] reads past the end of the allocated vector, triggering a heap-buffer-overflow confirmed by AddressSanitizer. Version 1.0.19 patches the issue.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

Out-of-bounds Write

  • Vulnerable module: libde265/libde265-0
  • Introduced through: libde265/libde265-0@1.0.11-1+deb12u2
  • Fixed in: 1.0.11-1+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libde265/libde265-0@1.0.11-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libde265 package and not the libde265 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in decoder_context::process_reference_picture_set() (libde265/decctx.cc:1376). The root cause is a missing aggregate bound check on predicted short-term reference picture set entries. Individual list sizes are validated, but the combined count after predicted RPS construction can exceed the 16-entry PocStFoll array, writing at index 16. Version 1.0.20 patches the issue.

Remediation

Upgrade Debian:12 libde265 to version 1.0.11-1+deb12u3 or higher.

References

low severity

Covert Timing Channel

  • Vulnerable module: libgcrypt20
  • Introduced through: libgcrypt20@1.10.1-3+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libgcrypt20@1.10.1-3+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libgcrypt20 package and not the libgcrypt20 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA ciphertexts.

Remediation

There is no fixed version for Debian:12 libgcrypt20.

References

low severity
new

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden reference graphs can repeatedly decode the same base image because processed_ids is copied per branch and ImageItem::decode_image() has no shared operation budget. This vulnerability is fixed in 1.23.2.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

CVE-2024-25269

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif <= 1.17.6 contains a memory leak in the function JpegEncoder::Encode. This flaw allows an attacker to cause a denial of service attack.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

CVE-2026-41069

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, a malformed HEIF sequence file can trigger an out-of-bounds read in core sequence parsing logic, causing DoS. A malformed file can have stco.entry_count == 0 (creating no chunks) while still passing validation because saio.entry_count == 0 matches, but with saiz.sample_count > 0 the SampleAuxInfoReader constructor still enters its loop. This leads to an out-of-bounds dereference on the empty chunks[0] in chunked mode.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and below contain a heap buffer overflow in MaskImageCodec::decode_mask_image(). When decoding a HEIF file containing a mask image (mski), the function copies the full iloc extent data into a pixel buffer using memcpy(dst, data.data(), data.size()). The copy length data.size() is determined by the iloc extent in the file (attacker-controlled), while the destination buffer is sized based on the declared image dimensions. Because no upper-bound check exists on the data length, a crafted file whose iloc extent exceeds the pixel buffer allocation overflows the heap. The vulnerable single-memcpy branch is reached when the mskC property specifies bits_per_pixel = 8 and the ispe property declares an even width ≥ 64 (so that stride == width), with no changes to default security limits or external codec plugins required. This issue has been fixed in version 1.22.0.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Improper Handling of Highly Compressed Data (Data Amplification)

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata and unci image data can cause decompress_brotli() and do_inflate() to grow accumulated output without an effective size limit or MemoryHandle accounting. The brotli path has no output bound, while the zlib path checks only a small temporary buffer in a branch that valid streams do not reach, and overlapping icef units can decompress the same payload repeatedly. HeifContext::interpret_heif_file_images() processes multiple compressed metadata items during file opening, allowing a small file to consume unbounded memory and terminate the process. This issue is fixed in version 1.23.2.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Information Exposure

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to decode and the library returns heif_error_Ok with no indication of failure, leading to an uninitialized heap memory information leak. The canvas is allocated via create_clone_image_at_new_size() → plane.alloc() → new (std::nothrow) uint8_t[allocation_size] which does not zero the memory; only the alpha plane is explicitly initialized via fill_plane(), so the Y, Cb, and Cr planes contain whatever was previously at that heap address. The failed tile's region of the canvas is never written. It retains uninitialized heap data that is delivered to the caller as decoded pixel values (4,096 bytes per Y/Cb/Cr plane = 12,288+ bytes total). Any application using libheif to decode grid-based HEIF/AVIF files with default settings is vulnerable: a crafted .heic or .avif file causes 4,096+ bytes of heap memory to appear as pixel values in the decoded image, and the calling application receives heif_error_Ok, so it has no indication the output contains heap garbage. In server-side image processing, an uploaded crafted HEIF decoded and re-encoded (e.g., as PNG/JPEG for thumbnails, CDN, social media) can leak cross-user data such as auth tokens, database results, and other users' image data. This issue has been fixed in version 1.22.0.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Information Exposure

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, two bugs in libheif chain to leak process heap memory as visible pixel values in decoded grid images. An attacker who uploads a crafted AVIF/HEIC file to any server-side image processor (WordPress, Sharp/libvips, ImageMagick, etc.) can recover heap data - including library function pointers sufficient to defeat ASLR, or any other secret - from the publicly-downloadable transcoded JPEG/PNG/WebP output. Local attack vectors are also possible. Version 1.22.0 fixes the issue.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in libheif/region.cc contains an integer overflow. Both width and height are unsigned int (32-bit) values parsed from the HEIF file. Their product can exceed UINT32_MAX, wrapping to a small value before the division by 8. This causes an undersized buffer allocation, leading to out-of-bounds memory access when the mask data is later interpreted as a width x height bitmap. Version 1.22.0 patches the issue.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.0, a crafted HEIF sequence accepted by heif_context_read_from_memory() with the msf1 sequence brand can cause unbounded heap allocation. In libheif/sequences/seq_boxes.cc, Box_stsz::parse() applies max_sequence_frames only to variable-size samples, so fixed-size mode accepts an attacker-controlled sample_count without a bound. In libheif/sequences/track.cc, Track::load() also adds current_sample_idx and samples_per_chunk in 32-bit arithmetic, allowing the consistency check to be bypassed by wraparound. The resulting values reach the Chunk::Chunk() allocation path, which can consume gigabytes of memory and crash or stall the process through memory exhaustion. This issue is fixed in version 1.23.0.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Integer Underflow

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.0 and earlier, a crafted HEIF or AVIF file containing a clean aperture box can reduce an image dimension to zero and crash or corrupt tiling results when heif_image_handle_get_image_tiling(handle, 1, &tiling) is called. ImageItem::get_heif_image_tiling() returns already transformed dimensions, and process_image_transformations_on_tiling() applies the clean aperture transformation again. The second application passes zero to Box_clap::left_rounded(0), where image_width minus one underflows and constructs Fraction(0xFFFFFFFF, 2). Debug builds reach an assertion and abort, while release builds can return a corrupt crop and zero-width tiling result. The affected implementation spans libheif/image-items/image_item.cc, libheif/context.cc, and libheif/box.cc. This issue is fixed in version 1.23.1.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Loop with Unreachable Exit Condition ('Infinite Loop')

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 100% CPU indefinitely with zero progress, leading to DoS. The loop has no iteration limit or timeout and is triggered during file open (parsing) - before any user interaction or image decoding. The process stays alive (no crash, no error logged), making it invisible to crash-based monitoring. This issue has been fixed in version 1.22.0.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Loop with Unreachable Exit Condition ('Infinite Loop')

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list data can make Track::init_sample_timing_table() compute a logical m_num_output_samples value that exceeds the uint32_t counters used by Track_Visual::decode_next_image_sample() and Track::get_next_sample_raw_data(). The resulting comparison can never reach the oversized output count, causing non-terminating decode or raw-sample loops and bypassing max_sequence_frames. The same sequence path repeatedly calls Box_stts::get_sample_duration() and allocates Chunk::m_sample_ranges and Track::m_presentation_timeline outside MemoryHandle accounting, allowing severe CPU and memory exhaustion from a small file. This issue is fixed in version 1.23.2.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap buffer over-read in HeifPixelImage::overlay() in libheif/pixelimage.cc. When compositing an overlay image (iovl) whose child image has a different bit depth for the alpha channel than for the color channels, the function indexes into the alpha plane using the color channel stride (in_stride) instead of the previously retrieved alpha_stride, causing reads past the end of the alpha buffer (up to 3,123 bytes for a 100×50 image with 10-bit color and 8-bit alpha). A crafted HEIF file can exploit this to cause a denial of service (crash) or potentially disclose adjacent heap memory through leaked bytes embedded in the decoded output pixels. This issue has been fixed in versionThis issue has been fixed in version 1.22.0.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder validates explicit icef compressed-unit offsets using unit_offset + unit_size. Because the addition can wrap, a crafted HEIF file can pass the range check and then construct a vector from iterators outside the compressed item buffer, producing an out-of-bounds heap read and crash. Version 1.22.1 patches the issue.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.0, Track::init_sample_timing_table() in libheif/sequences/track.cc stores an out-of-bounds chunk index (m_chunks.size()) into m_presentation_timeline when the number of chunks defined in the stco box is less than the number of samples in stsz. A subsequent call to heif_track_get_next_raw_sequence_sample() reads m_chunks[chunk_idx] with that OOB index, causing a heap-buffer-overflow. Version 1.22.0 fixes the issue.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed HEIF image using generic zlib unci full-item compression can crash an application that decodes an advertised tile with heif_image_handle_decode_image_tile(). In libheif/codecs/uncompressed/unc_decoder.cc, unc_decoder::fetch_tile_data() computes a large tile offset and unc_decoder::get_compressed_image_data_uncompressed() validates it with range_start_offset plus range_size. For the last advertised tile (4095, 4095), the addition can wrap to zero, bypass the bounds check, and pass an invalid source pointer and a one-terabyte length to memcpy. The observed result is an out-of-bounds read and process crash; opening the file alone does not trigger the issue because tile decoding is required. This issue is fixed in version 1.23.1.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of unc_decoder::get_compressed_image_data_uncompressed() in libheif/codecs/uncompressed/unc_decoder.cc retains an addition-based range check that can wrap when a crafted uncompressed tile grid produces a large range_start_offset and range_size. The overflow makes the bounds comparison pass and allows heif_image_handle_decode_image_tile() to call memcpy() with an invalid source pointer and a very large length when decoding a valid high-index advertised tile. This incomplete remediation of CVE-2026-62292 can reliably crash tile-processing applications, while whole-image decoding is not claimed to reach the demonstrated path. This issue is fixed in version 1.23.3.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inline_mask_data() function in libheif/api/libheif/heif_regions.cc accepts mask_data_len without verifying that it equals the byte count required by width and height. A later heif_region_get_mask_image() call derives the read length from the region geometry, so an undersized stored buffer causes heif_region_get_inline_mask_image() to read beyond the heap allocation and copy adjacent bytes into the returned monochrome mask image. This can disclose heap data or crash an application that constructs region metadata through the writer API, while the file-parsing path is not affected because it validates the canonical mask size. This issue is fixed in version 1.23.2.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Out-of-bounds Read

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() stores image-plane strides in an integer width that can overflow for extremely large RGB images created through heif_image_create() and heif_image_add_plane(). The resulting wrapped stride causes the conversion loop in libheif/color-conversion/rgb2yuv.cc to compute an invalid input pointer and read beyond the allocated interleaved plane while heif_context_encode_image() performs RGB-to-YCbCr conversion. This can crash the encoding process. This issue is fixed in version 1.19.6.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

Out-of-bounds Write

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.21.2 and prior contain a heap-buffer-overflow (write) vulnerability in the grid tile compositing, allowing an attacker to write 64 bytes of fully attacker-controlled data past the end of a chroma plane heap allocation by crafting a HEIF/AVIF file with a 1×4 grid of odd-height tiles. The overflow is triggered during normal image decoding with default build configuration. The written bytes are chroma (Cb/Cr) pixel values from the attacking tile, giving the attacker full control over the overflow content. This issue has been fixed in version 1.22.0.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Out-of-bounds Write

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, heif_context_add_image_tile() accepts an independently constructed tile whose component-plane dimensions do not match the tile geometry established by the prototype image. ImageItem_uncompressed::add_image_tile() passes that tile directly to unc_encoder::encode_tile(), which lacked the check_component_sizes() gate and sizes its output from the configured tile geometry while copying the tile's actual component-plane dimensions. An oversized component plane can therefore make unc_encoder_component_interleave::encode_tile() copy attacker-controlled data beyond the heap output buffer. This issue is fixed in version 1.23.2.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity
new

Reachable Assertion

  • Vulnerable module: libheif/libheif1
  • Introduced through: libheif/libheif1@1.15.1-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libheif/libheif1@1.15.1-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libheif package and not the libheif package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a clap property and an ispe width or height greater than INT32_MAX + 1 can reach crop calculations through heif_image_handle_get_image_tiling(). Box_clap::left_rounded() or Box_clap::top_rounded() passes the image dimension minus one to Fraction::Fraction(), whose uint32_t constructor uses an assertion as input validation, causing assert-enabled builds to abort. Release builds can instead compute invalid crop geometry, and the tiling API returns dimensions that the normal decode security limits reject. This issue is fixed in version 1.23.3.

Remediation

There is no fixed version for Debian:12 libheif.

References

low severity

CVE-2025-28162

  • Vulnerable module: libpng1.6/libpng-dev
  • Introduced through: libpng1.6/libpng-dev@1.6.39-2+deb12u5 and libpng1.6/libpng16-16@1.6.39-2+deb12u5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng-dev@1.6.39-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng16-16@1.6.39-2+deb12u5

NVD Description

Note: Versions mentioned in the description apply only to the upstream libpng1.6 package and not the libpng1.6 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via the pngimage with AddressSanitizer (ASan), the program leaks memory in various locations, eventually leading to high memory usage and causing the program to become unresponsive

Remediation

There is no fixed version for Debian:12 libpng1.6.

References

low severity
new

CVE-2026-46675

  • Vulnerable module: libpng1.6/libpng-dev
  • Introduced through: libpng1.6/libpng-dev@1.6.39-2+deb12u5 and libpng1.6/libpng16-16@1.6.39-2+deb12u5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng-dev@1.6.39-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng16-16@1.6.39-2+deb12u5

NVD Description

This vulnerability has not been analyzed by NVD yet.

Remediation

There is no fixed version for Debian:12 libpng1.6.

References

low severity

Memory Leak

  • Vulnerable module: libpng1.6/libpng-dev
  • Introduced through: libpng1.6/libpng-dev@1.6.39-2+deb12u5 and libpng1.6/libpng16-16@1.6.39-2+deb12u5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng-dev@1.6.39-2+deb12u5
  • Introduced through: buildpack-deps@bookworm › libpng1.6/libpng16-16@1.6.39-2+deb12u5

NVD Description

Note: Versions mentioned in the description apply only to the upstream libpng1.6 package and not the libpng1.6 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Buffer Overflow vulnerability in libpng 1.6.43-1.6.46 allows a local attacker to cause a denial of service via png_create_read_struct() function.

Remediation

There is no fixed version for Debian:12 libpng1.6.

References

low severity

Out-of-bounds Write

  • Vulnerable module: libtasn1-6
  • Introduced through: libtasn1-6@4.19.0-2+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libtasn1-6@4.19.0-2+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libtasn1-6 package and not the libtasn1-6 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Stack-based buffer overflow in libtasn1 version: v4.20.0. The function fails to validate the size of input data resulting in a buffer overflow in asn1_expend_octet_string.

Remediation

There is no fixed version for Debian:12 libtasn1-6.

References

low severity
new

Heap-based Buffer Overflow

  • Vulnerable module: libx11/libx11-6
  • Introduced through: libx11/libx11-6@2:1.8.4-2+deb12u2, libx11/libx11-data@2:1.8.4-2+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libx11/libx11-6@2:1.8.4-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › libx11/libx11-data@2:1.8.4-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › libx11/libx11-dev@2:1.8.4-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libx11 package and not the libx11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.

Remediation

There is no fixed version for Debian:12 libx11.

References

low severity
new

Out-of-bounds Read

  • Vulnerable module: libx11/libx11-6
  • Introduced through: libx11/libx11-6@2:1.8.4-2+deb12u2, libx11/libx11-data@2:1.8.4-2+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libx11/libx11-6@2:1.8.4-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › libx11/libx11-data@2:1.8.4-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › libx11/libx11-dev@2:1.8.4-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libx11 package and not the libx11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An out-of-bounds read vulnerability in libX11's XIM trigger-key registration parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.

Remediation

There is no fixed version for Debian:12 libx11.

References

low severity
new

Out-of-bounds Read

  • Vulnerable module: libx11/libx11-6
  • Introduced through: libx11/libx11-6@2:1.8.4-2+deb12u2, libx11/libx11-data@2:1.8.4-2+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libx11/libx11-6@2:1.8.4-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › libx11/libx11-data@2:1.8.4-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › libx11/libx11-dev@2:1.8.4-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libx11 package and not the libx11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An out-of-bounds read in libX11's byte-oriented codeset parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.

Remediation

There is no fixed version for Debian:12 libx11.

References

low severity
new

Out-of-bounds Read

  • Vulnerable module: libx11/libx11-6
  • Introduced through: libx11/libx11-6@2:1.8.4-2+deb12u2, libx11/libx11-data@2:1.8.4-2+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libx11/libx11-6@2:1.8.4-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › libx11/libx11-data@2:1.8.4-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › libx11/libx11-dev@2:1.8.4-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream libx11 package and not the libx11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An out-of-bounds read vulnerability in libX11's XIM (X Input Method) attribute parser in libX11 before 1.8.14 could be used by malicious X servers to crash attached X clients.

Remediation

There is no fixed version for Debian:12 libx11.

References

low severity

CVE-2026-6653

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via maliciously crafted XML input with improper entity resolution handling.

Remediation

There is no fixed version for Debian:12 libxml2.

References

low severity

Stack-based Buffer Overflow

  • Vulnerable module: libxml2
  • Introduced through: libxml2@2.9.14+dfsg-1.3~deb12u6 and libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxml2@2.9.14+dfsg-1.3~deb12u6
  • Introduced through: buildpack-deps@bookworm › libxml2/libxml2-dev@2.9.14+dfsg-1.3~deb12u6

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxml2 package and not the libxml2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds checking. By supplying an overly long input line, an attacker can overflow internal buffers (command, arg, and argv) during input parsing. This results in memory corruption within the stack frame. Successful exploitation may cause a crash or potentially allow arbitrary code execution in the context of the xmlcatalog process.

This issue has been fixed in the commit c2e233fc.

NOTE: The maintainers of this project did not agree that this issue is a vulnerability and considered it a bug.

Remediation

There is no fixed version for Debian:12 libxml2.

References

low severity
new

Heap-based Buffer Overflow

  • Vulnerable module: libxrender/libxrender-dev
  • Introduced through: libxrender/libxrender-dev@1:0.9.10-1.1 and libxrender/libxrender1@1:0.9.10-1.1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › libxrender/libxrender-dev@1:0.9.10-1.1
  • Introduced through: buildpack-deps@bookworm › libxrender/libxrender1@1:0.9.10-1.1

NVD Description

Note: Versions mentioned in the description apply only to the upstream libxrender package and not the libxrender package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject code into attached X clients.

Remediation

There is no fixed version for Debian:12 libxrender.

References

low severity

Incorrect Authorization

  • Vulnerable module: mariadb/libmariadb-dev
  • Introduced through: mariadb/libmariadb-dev@1:10.11.18-0+deb12u1, mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb-dev-compat@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/libmariadb3@1:10.11.18-0+deb12u1
  • Introduced through: buildpack-deps@bookworm › mariadb/mariadb-common@1:10.11.18-0+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream mariadb package and not the mariadb package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

MariaDB server is a community developed fork of MySQL server. From versions 11.4.1 to before 11.4.11, 11.8.1 to before 11.8.7, and 12.3.1, a user getting EXECUTE access to a stored routine via a role, could see the routine definition even without SHOW CREATE ROUTINE privilege. This issue has been patched in versions 11.4.11, 11.8.7, and 12.3.2.

Remediation

There is no fixed version for Debian:12 mariadb.

References

low severity

CVE-2024-31047

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue in Academy Software Foundation openexr v.3.2.3 and before allows a local attacker to cause a denial of service (DoS) via the convert function of exrmultipart.cpp.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity
new

CVE-2026-88384

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file containing an unknown-type attribute with dataSize set to zero causes the parser to create an opaque attribute with a NULL packed_data pointer. The OpaqueAttribute constructor passes the NULL pointer to memcpy() without validating the zero-size condition, resulting in undefined behavior and process termination, leading to denial of service.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27946.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27948.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Academy Software Foundation OpenEXR EXR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Academy Software Foundation OpenEXR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the parsing of EXR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-27947.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, a crafted tiled EXR can trigger a heap out-of-bounds write on 32-bit/ILP32 builds when read through the public TiledRgbaInputFile RGBA API. The file uses a small 40x40 dataWindow but a 65537x65537 tile size. On ILP32, the Array2D<Rgba> tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.13 are vulnerable to a heap out-of-bounds write when exrmetrics reads a crafted deep scanline EXR. This occurs with pixel conversion options such as --pixelmode float or --bench because DeepSlice requests FLOAT output while the backing sample buffers are allocated using the input HALF element size. The issue is fixed in versions 3.3.13 and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Heap-based Buffer Overflow

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, exrmultiview can write past a heap allocation when it combines two attacker-supplied, individually valid scanline EXR files whose union dataWindow is not aligned to one view's channel subsampling. The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write. The trigger is normal public-tool processing, such as exrmultiview left A.exr right B.exr out.exr with crafted but valid inputs, so this is not solely an API or caller-precondition issue. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Improper Input Validation

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used in the motion picture industry. Versions 3.4.0 through 3.4.12 contain a NULL pointer dereference in the OpenEXRCore function exr_attr_set_bytes(). The public setter validates the top-level exr_attr_bytes_t value pointer but does not verify that the nested type_hint pointer is non-NULL when hint_length is greater than zero. When a caller supplies a positive hint_length together with a NULL type_hint, exr_attr_bytes_create() allocates a destination type-hint buffer and then copies from the NULL source pointer, causing a deterministic crash. The flaw is reachable through the public OpenEXRCore C API and results in a denial of service. The issue is fixed in version 3.4.13.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Incorrect Type Conversion or Cast

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a misaligned memory write vulnerability exists in LossyDctDecoder_execute() in src/lib/OpenEXRCore/internal_dwa_decoder.h:749. When decoding a DWA or DWAB-compressed EXR file containing a FLOAT-type channel, the decoder performs an in-place HALF→FLOAT conversion by casting an unaligned uint8_t * row pointer to float * and writing through it. Because the row buffer may not be 4-byte aligned, this constitutes undefined behavior under the C standard and crashes immediately on architectures that enforce alignment (ARM, RISC-V, etc.). On x86 it is silently tolerated at runtime but remains exploitable via compiler optimizations that assume aligned access. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From 3.2.0 to before 3.2.7, 3.3.9, and 3.4.9, a signed integer overflow exists in undo_pxr24_impl() in src/lib/OpenEXRCore/internal_pxr24.c at line 377. The expression (uint64_t)(w * 3) computes w * 3 as a signed 32-bit integer before casting to uint64_t. When w is large, this multiplication constitutes undefined behavior under the C standard. On tested builds (clang/gcc without sanitizers), two's-complement wraparound commonly occurs, and for specific values of w the wrapped result is a small positive integer, which may allow the subsequent bounds check to pass incorrectly. If the check is bypassed, the decoding loop proceeds to write pixel data through dout, potentially extending far beyond the allocated output buffer. This vulnerability is fixed in 3.2.7, 3.3.9, and 3.4.9.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3.3.11, and 3.4.0 to before 3.4.11, there is an integer overflow in ImageChannel::resize that leads to heap OOB write via OpenEXRUtil public API. This issue has been patched in versions 3.2.9, 3.3.11, and 3.4.11.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12, and 3.4.13 contain an infinite-loop vulnerability in SampleCountChannel. The helper roundListSizeUp() rounds a sample-list size up to the next power of two using repeated unsigned left shifts, which terminates for normal values but fails for UINT_MAX: the sequence reaches 0x80000000, and the next left shift wraps the 32-bit value to 0. Because 0 remains less than UINT_MAX, the loop never progresses and never exits. The bug is reachable through public OpenEXRUtil APIs, either by editing the sample-count buffer through SampleCountChannel::Edit (whose destructor calls endEdit()) or by calling SampleCountChannel::set(x, y, UINT_MAX) on a valid pixel. This issue has been fixed in versions 3.2.10, 3.3.12, and 3.4.13.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a reachable assertion failure in the HTJ2K decode path allows a crafted HTJ2K-compressed EXR file to cause an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, an int32_t multiplication in OpenEXRCore's unpack_sample_table() can overflow while decoding a crafted deep tiled EXR file, producing an invalid pointer that leads to a read from an unmapped memory address and a crash. Because the overflow occurs in the standard decoding path (exr_decoding_run), any application that decodes deep tiled EXR files is affected. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Integer Overflow or Wraparound

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 can return an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin. This vulnerability occurs because the API combines zero-based row access with an absolute-coordinate-adjusted base pointer, allowing a crash or limited information disclosure. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Out-of-bounds Read

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable to crashing. This occurs when Imf::GetChannelsInMultiPartFile() processes a crafted EXR with an empty multiView header attribute and Imf::viewFromChannelName() indexes the empty vector for a dotless channel name. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Out-of-bounds Read

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds read. The vulnerability is reached when a crafted uncompressed deep-tile EXR causes the sample-count table size calculation in OpenEXRCore decoding.c to wrap before unpack_sample_table() iterates over the full attacker-controlled tile dimensions, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Out-of-bounds Read

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.2.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to a heap out-of-bounds read. The issue occurs when a crafted RLE-compressed EXR causes the 64-bit unpacked size to truncate before allocation in OpenEXRCore decoding.c and unpack_32bit() reads beyond the resulting buffer, allowing denial of service. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Out-of-bounds Read

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In OpenEXRUtil versions 3.3.0 through 3.3.12 and 3.4.0 through 3.4.12, the documented TypedDeepImageChannel<T>::row() API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout. The flaw arises because ImfDeepImageChannel uses two conflicting coordinate models: at(x, y) uses absolute coordinates (with _base offset by dataWindow.min), while row(r) is documented as 0-based logical access. For a non-zero dataWindow.min, row(0) therefore points outside the _sampleListPointers allocation instead of at the first logical row. This issue is fixed in versions 3.3.13 and 3.4.13.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Out-of-bounds Read

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image file format, widely used in the motion picture industry. In versions through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13, the OpenEXRUtil library returns an out-of-bounds pointer from the SampleCountChannel::row() API when a deep image has a non-zero dataWindow origin. The row() accessor is documented as 0-based and computes its address from an internal base that is offset for absolute pixel coordinates, so the two coordinate models conflict whenever dataWindow.min is non-zero. For a deep image whose data window has a large negative vertical origin, row(0) points far outside the allocated sample-count buffer. An application that opens an attacker-controlled deep EXR file and accesses sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Out-of-bounds Write

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions prior to 3.2.10, 3.3.12 and 3.4.13 contain a heap out-of-bounds write in Imf_4_0::SampleCountChannel::set(int r, unsigned int newNumSamples[]). The row-based sample-count setter computes the target Y coordinate with dataWindow.min.x instead of dataWindow.min.y. For a valid deep image data window where min.x != min.y, a valid row index can be translated into an invalid Y coordinate, causing writes before the allocated _numSamples buffer. The vulnerability is reachable through the public OpenEXRUtil DeepImage API and can lead to heap corruption and process crashes. This issue has been fixed in versions 3.2.10, 3.3.12 and 3.4.13.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Out-of-bounds Write

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. OpenEXR versions 3.1.0 through 3.2.10, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 are vulnerable on ILP32 builds to an out-of-bounds write. When a crafted B44-compressed scanline EXR causes the logical scratch size to truncate before allocation and uncompress_b44_impl() writes using the attacker-controlled channel width, allowing denial of service and memory corruption. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Reachable Assertion

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. In versions 3.4.0 through 3.4.12, a crafted HTJ2K-compressed EXR file causes an unconditional process abort in any application that calls exr_start_read() on untrusted input, resulting in denial of service. The crash is triggered by a QCD marker whose lower five bits are zero, which OpenEXR passes into the vendored OpenJPH library while constructing the codestream and evaluating its quantization delta parameters. OpenJPH uses an assertion rather than a recoverable error to validate those bits, so any invalid value calls abort() directly and cannot be intercepted by surrounding error handling, a problem compounded by OpenEXR wrapping only its internal HT header parser in error handling while leaving the later codestream read and construction calls unprotected. This issue has been resolved in version 3.4.13.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Stack-based Buffer Overflow

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. From version 3.4.0 through 3.4.13, a crafted HTJ2K-compressed EXR can crash OpenEXR during normal decode. An HTJ2K-compressed EXR whose JPEG 2000 SIZ fields place the first tile outside the visible image can reach invalid tile and codeblock geometry in the vendored OpenJPH AVX2 decoder, causing a stack out-of-bounds write and denial of service. OpenEXR's HTJ2K path validates the decoded codestream dimensions against the EXR chunk size, but it does not reject SIZ image-offset/tile-grid geometry where the first tile does not intersect the image. This issue is fixed in version 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Use After Free

  • Vulnerable module: openexr/libopenexr-3-1-30
  • Introduced through: openexr/libopenexr-3-1-30@3.1.5-5 and openexr/libopenexr-dev@3.1.5-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-3-1-30@3.1.5-5
  • Introduced through: buildpack-deps@bookworm › openexr/libopenexr-dev@3.1.5-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openexr package and not the openexr package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture industry. Versions before 3.2.11, 3.3.0 through 3.3.12, and 3.4.0 through 3.4.13 allow a crafted EXR with a nonzero dataWindow.min to make TypedFlatImageChannel::row() return an invalid heap pointer, causing out-of-bounds or use-after-free writes. This occurs when an application writes rows through FlatHalfChannel::row(). Affected consumers are tools, converters, render pipeline components, or image-processing services that accept untrusted EXR files and use FlatHalfChannel::row() on loaded images. This issue is fixed in versions 3.2.11, 3.3.13, and 3.4.14.

Remediation

There is no fixed version for Debian:12 openexr.

References

low severity

Resource Exhaustion

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in OpenJPEG. Maliciously constructed pictures can cause the program to enter a large loop and continuously print warning messages on the terminal.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Resource Exhaustion

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A flaw was found in OpenJPEG. A resource exhaustion can occur in the opj_t1_decode_cblks function in tcd.c through a crafted image file, causing a denial of service.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Resource Exhaustion

  • Vulnerable module: openjpeg2/libopenjp2-7
  • Introduced through: openjpeg2/libopenjp2-7@2.5.0-2+deb12u3 and openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7@2.5.0-2+deb12u3
  • Introduced through: buildpack-deps@bookworm › openjpeg2/libopenjp2-7-dev@2.5.0-2+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream openjpeg2 package and not the openjpeg2 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A vulnerability was found in OpenJPEG similar to CVE-2019-6988. This flaw allows an attacker to bypass existing protections and cause an application crash through a maliciously crafted file.

Remediation

There is no fixed version for Debian:12 openjpeg2.

References

low severity

Out-of-bounds Read

  • Vulnerable module: openldap/libldap-2.5-0
  • Introduced through: openldap/libldap-2.5-0@2.5.13+dfsg-5

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openldap/libldap-2.5-0@2.5.13+dfsg-5

NVD Description

Note: Versions mentioned in the description apply only to the upstream openldap package and not the openldap package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenLDAP Lightning Memory-Mapped Database (LMDB) versions up to and including 0.9.14, prior to commit 8e1fda8, contain a heap buffer underflow in the readline() function of mdb_load. When processing malformed input containing an embedded NUL byte, an unsigned offset calculation can underflow and cause an out-of-bounds read of one byte before the allocated heap buffer. This can cause mdb_load to crash, leading to a limited denial-of-service condition.

Remediation

There is no fixed version for Debian:12 openldap.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

sshd in OpenSSH before 10.4 does not always honor the minimum authentication delay.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Allocation of Resources Without Limits or Throttling

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

sshd in OpenSSH before 10.4 allows remote attackers to cause a denial of service (resource consumption from excessive authentication attempts) because MaxAuthTries was mishandled for GSSAPIAuthentication.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Always-Incorrect Control Flow Implementation

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_keys) was supposed to be applicable to tunnel forwarding but was not.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Directory Traversal

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Directory Traversal

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Improper Following of Specification by Caller

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Improper Validation of Specified Quantity in Input

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Incorrect Resource Transfer Between Spheres

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that add tokens or use keys. This is caused by misinteraction between agent locking and the session-bind@openssh.com extension.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Use After Free

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

ssh in OpenSSH before 10.4 can have a use-after-free when a server changes its host key during a key re-exchange. (This outcome occurs only on the client side.)

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Use After Free

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operations are concurrent.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

Use of Less Trusted Source

  • Vulnerable module: openssh/openssh-client
  • Introduced through: openssh/openssh-client@1:9.2p1-2+deb12u10

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssh/openssh-client@1:9.2p1-2+deb12u10

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssh package and not the openssh package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

In sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.

Remediation

There is no fixed version for Debian:12 openssh.

References

low severity

CVE-2025-27587

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

OpenSSL 3.0.0 through 3.3.2 on the PowerPC architecture is vulnerable to a Minerva attack, exploitable by measuring the time of signing of random messages using the EVP_DigestSign API, and then using the private key to extract the K value (nonce) from the signatures. Next, based on the bit size of the extracted nonce, one can compare the signing time of full-sized nonces to signatures that used smaller nonces, via statistical tests. There is a side-channel in the P-364 curve that allows private key extraction (also, there is a dependency between the bit size of K and the size of the side channel). NOTE: This CVE is disputed because the OpenSSL security policy explicitly notes that any side channels which require same physical system to be detected are outside of the threat model for the software. The timing signal is so small that it is infeasible to be detected without having the attacking process running on the same physical system.

Remediation

There is no fixed version for Debian:12 openssl.

References

low severity
new

CVE-2026-35189

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: A certificate with many nameRelativeToCRLIssuer CRL distribution points causes disproportionate heap growth when OpenSSL caches X.509 extensions.

Impact summary: Receiving a crafted certificate from a malicious peer can lead to significant memory pressure and possible Denial of Service in clients or in servers that solicit client certificates.

CWE: CWE-770: Allocation of Resources Without Limits or Throttling

Description: A certificate or a set of certificates that fits under the limit for size of certificates accepted from the peer (~100 KiB) can result in allocation of several hundred MiB of resident memory on the receiving side during a normal TLS handshake. This may be enough to crash the client or server, if multiple concurrent connections lead to similarly large memory allocations.

The fix postpones processing of the CRL distribution points extensions in certificates to the time when the processed value is required for CRL processing. This avoids keeping large memory allocations for a long time when such certificates are received.

FIPS impact: no The affected code is outside the FIPS module boundary.

Remediation

There is no fixed version for Debian:12 openssl.

References

low severity

CVE-2026-42767

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others
  • Fixed in: 3.0.22-1~deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: An attacker-controlled CMP (Certificate Management Protocol) server could trigger a NULL pointer dereference in a CMP client application.

Impact summary: A NULL pointer dereference causes a crash of the application and a Denial of Service.

An attacker controlling a CMP server (or acting as a man-in-the-middle) could craft a CMP response containing a CRMF (Certificate Request Message Format) CertRepMessage with an EncryptedValue structure where the symmAlg field has an algorithm OID but no parameters field. When the OpenSSL CMP client processes this response, the NULL dereference occurs, causing a crash of the CMP client.

Applications that process untrusted CMP/CRMF messages may be affected.

The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this issue, as the affected code is outside the OpenSSL FIPS module boundary.

Remediation

Upgrade Debian:12 openssl to version 3.0.22-1~deb12u1 or higher.

References

low severity
new

CVE-2026-54872

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: The generic elliptic-curve scalar multiplication used for ECDSA and SM2 signature operations with curves that do not have a dedicated implementation leaks information about the secret nonce through timing.

Impact summary: An attacker able to measure signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.

CWE: CWE-208: Observable Timing Discrepancy

Description: The generic elliptic-curve scalar multiplication used for curves that do not have a dedicated constant-time implementation pads the secret scalar with non-constant-time BIGNUM operations, so the time taken depends on the value of the secret scalar derived from the ECDSA and SM2 nonce.

The leak is very small; observing it requires a large number of measurements. The effect is largest for curves whose group order lies on a machine-word boundary, such as brainpoolP384r1.

Applications using ECDSA signing over the Brainpool and other generic prime curves, and SM2 signing on platforms that use the generic implementation, are vulnerable to this issue.

The NIST curves P-256, P-384 and P-521 use dedicated constant-time implementations and are not affected.

FIPS Impact: no The FIPS modules are not affected: the approved NIST curves used in the FIPS provider have dedicated constant-time implementations and do not use the affected code path.

Remediation

There is no fixed version for Debian:12 openssl.

References

low severity

CVE-2026-54874

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others
  • Fixed in: 3.0.22-1~deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: Receiving a DTLS record for a future epoch while a handshake is in progress causes OpenSSL to buffer far more memory than the record itself requires.

Impact summary: A peer can use a small amount of network traffic to make an OpenSSL DTLS endpoint retain a disproportionately large amount of memory, which may lead to a Denial of Service.

CWE: CWE-405: Asymmetric Resource Consumption (Amplification)

Description: While a DTLS handshake is in progress, a peer may legitimately have already moved on to the next epoch (for example, having sent its ChangeCipherSpec and Finished messages) before the local endpoint has processed the same transition, typically because of reordering on the underlying UDP transport. OpenSSL buffers such early records so that they can be processed once the local endpoint catches up.

Buffering a record currently retains the entire read buffer it arrived in, which is sized to hold the largest possible DTLS record (around 16 kilobytes), rather than just the bytes that make up the record itself. Up to 100 such records may be buffered per connection. As a result, a peer that sends a stream of small forged records claiming to belong to the next epoch can cause an OpenSSL DTLS endpoint to retain around 1.7 megabytes of memory, despite sending only a small fraction of that amount of data over the network.

An attacker therefore gains a memory amplification factor of around 1200, and can multiply the effect across as many associations as it is able to open, making this a remote memory exhaustion Denial of Service risk for DTLS servers. Since the memory retained per connection remains bounded, and any limit an application already places on the number of concurrent associations also bounds the total exposure, this issue has been assessed as Low severity.

FIPS impact: no

No FIPS modules are affected by this issue as the affected code is outside the OpenSSL FIPS module boundary.

OpenSSL 4.0, 3.6, 3.5, 3.4, 3.0, 1.1.1 and 1.0.2 are vulnerable to this issue.

OpenSSL 4.0 users should upgrade to OpenSSL 4.0.2. OpenSSL 3.6 users should upgrade to OpenSSL 3.6.4. OpenSSL 3.5 users should upgrade to OpenSSL 3.5.8. OpenSSL 3.4 users should upgrade to OpenSSL 3.4.7. OpenSSL 3.0 users should upgrade to OpenSSL 3.0.22.

Premium support customers only: OpenSSL 1.1.1 users should upgrade to OpenSSL 1.1.1zi OpenSSL 1.0.2 users should upgrade to OpenSSL 1.0.2zr

This issue was reported on 18 May 2026 by Amazon Web Services. The fix has been developed by Matt Caswell.

-- cut (non-publishing metadata for internal use) -- Reported by: Amazon Web Services Fixed by: Matt Caswell

Remediation

Upgrade Debian:12 openssl to version 3.0.22-1~deb12u1 or higher.

References

low severity

CVE-2026-63072

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others
  • Fixed in: 3.0.22-1~deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buffer based on querying the unwrapped key size, but the AES-WRAP-PAD unwrap primitive can write and cleanse more bytes than that query reports, causing an 8-byte out-of-bounds heap write.

Impact summary: An attacker who supplies a crafted CMS message can trigger a deterministic 8-byte out-of-bounds heap write when the victim decrypts it with CMS_decrypt(), corrupting the heap and typically resulting in a Denial of Service.

CWE: CWE-787: Out-of-bounds Write

Description: The key-wrap OID is potentially attacker-controlled on the wire. CMS unwrapping allows both id-aesNNN-wrap-pad and id-aesNNN-wrap ciphers. An attacker can take a legitimate message and change a single OID byte to select the padded variant while leaving the message otherwise valid. Since the unwrap key is derived from the recipient's private operation (ECDH key agreement or ML-KEM decapsulation), the RFC 5649 integrity check cannot pass, and the decryption fails with integrity failure.

The write is a fixed-size (8-byte), fixed-value (zero) heap overflow immediately past the allocation, requires no special configuration, and is reachable from the public CMS_decrypt() function. The consequence is a heap corruption leading to a Denial of Service. The fix in the CMS code sizes the unwrap output buffer for the worst case so a failed unwrap cannot write past the allocation.

FIPS impact: no

As the CMS code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

Remediation

Upgrade Debian:12 openssl to version 3.0.22-1~deb12u1 or higher.

References

low severity

CVE-2026-63074

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others
  • Fixed in: 3.0.22-1~deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: The OpenSSL Certificate Management Protocol (CMP) caches additional certificates (extraCerts) sent in a CMP message, but never expunges them (for instance if they are invalid). If a server reuses an OSSL_CMP_CTX frequently, this cache of extraCerts may grow unboundedly, and a malicious client may flood a CMP server with requests driving this growth.

Impact summary: Users utilizing a CMP server that reuses a single OSSL_CMP_CTX for the lifetime of a server process may observe unbounded memory growth in the event a malicious client repeatedly sends requests containing unique extra certificates, which may lead to OOM conditions.

CWE: CWE-770: Allocation of Resources Without Limits or Throttling

Description: If a remote user sends CMP messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remains in the server contexts untrusted certificate stack. This exposes servers with long lived ctx objects to Denial of Service attacks in which an attacker sends messages intending to be rejected with a large list of additional certificates repeatedly, forcing the server to store them indefinitely.

The issue was fixed by removing the added extra certs if the message is rejected, using the same method as when the context is configured to not do caching at all.

FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

Remediation

Upgrade Debian:12 openssl to version 3.0.22-1~deb12u1 or higher.

References

low severity

CVE-2026-63076

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others
  • Fixed in: 3.0.22-1~deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: OpenSSL CMP password based protection verification only checks whether the protectionAlg parameter was not NULL and not its ASN.1 type, before treating it as a PBMParameter. A crafted message can contain a parameter of a different type, which is then dereferenced as an invalid pointer.

Impact summary: A remote, unauthenticated attacker can crash an application acting as a CMP server that accepts PBM-protected messages, or a CMP client talking to a malicious or intercepted CMP server, resulting in a Denial of Service.

CWE: CWE-476: NULL Pointer Dereference

Description: When verifying the password-based MAC protection of a CMP message, OpenSSL library reads the protectionAlg algorithm parameter with X509_ALGOR_get0(), which returns both the parameter type and its value pointer. The value is then cast to an ASN1_STRING and treated as the expected PBMParameter after only checking that pointer is not NULL. The parameter type returned by X509_ALGOR_get0() was never consulted.

This happens during protection verification, before any MAC is computed, so no knowledge of the PBM shared secret is required; the only precondition is that PBM verification is reachable. On the server side this is reached from OSSL_CMP_SRV_process_request() for any application that stands up a CMP server accepting PBM-protected messages, and on the client side from CMP response validation against a malicious or on-path (MITM) server. The reliable consequence is a denial of service; there is no memory disclosure, no controlled memory write, and no path to code execution. CMP is a specialized feature that an application must explicitly enable.

FIPS impact: no As the CMP code lives outside the FIPS module boundary, no FIPS modules are affected by this CVE.

Remediation

Upgrade Debian:12 openssl to version 3.0.22-1~deb12u1 or higher.

References

low severity

CVE-2026-75803

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others
  • Fixed in: 3.0.22-1~deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying the supplied authentication tag when the operation is finalized by calling the EVP_Cipher() function.

Impact summary: Applications calling EVP_Cipher() on an empty ciphertext and expecting the call to check the AEAD tag may accept forged messages.

CWE: CWE-354 (Improper Validation of Integrity Check Value)

Description: The EVP_Cipher() API call for AEAD ciphers behaves like a one shot encryption and decryption call. It also verifies the AEAD tag after the decryption operation. However for AES-OCB and ChaCha20-Poly1305 ciphers it skipped the AEAD tag verification when an empty ciphertext was passed to the function. The callers of this function might believe that a successful return indicates a valid AEAD tag for these ciphers, even when that has not truly been validated in this case.

FIPS impact: no The FIPS modules in 4.0, 3.6, 3.5, 3.4, and 3.0 are not affected by this CVE as the affected algorithms are not FIPS approved and thus not implemented in the FIPS module.

Remediation

Upgrade Debian:12 openssl to version 3.0.22-1~deb12u1 or higher.

References

low severity
new

CVE-2026-75805

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: A CMP client that requests certificate revocation on the basis of a PKCS#10 CSR may dereference a NULL pointer and terminate abnormally when processing a crafted revocation response.

Impact summary: The NULL pointer dereference happens on a read which leads to a crash and a Denial of Service for the affected client application.

CWE: CWE-476: NULL-pointer dereference

Description: A CMP client revoking a certificate has to tell the server which certificate to revoke, and may do so by supplying a PKCS#10 CSR instead of the certificate itself or its issuer name and serial number. This is 'openssl cmp -cmd rr -csr <file>' on the command line, or OSSL_CMP_exec_RR_ses() with the certificate supplied via OSSL_CMP_CTX_set1_p10CSR() through the API.

A CSR does not contain the issuer name and serial number of the certificate, so the client does not send them. A server may optionally name the certificate it revoked in its response, and the client then compares that name against what it sent. Having sent neither an issuer name nor a serial number, it has nothing to compare against, and a server returning a specially crafted name causes the client to read from a NULL pointer and crash.

The revocation response is checked for valid message protection before the affected code is reached, so an attacker must be a malicious or compromised CMP server, or a man-in-the-middle in possession of the secret used for message protection. Clients that identify the certificate to be revoked by a certificate or by issuer and serial number rather than by a PKCS#10 CSR are not affected.

FIPS impact: no No FIPS modules are affected by this issue, as the CMP protocol implementation is outside the OpenSSL FIPS module boundary.

Remediation

There is no fixed version for Debian:12 openssl.

References

low severity
new

CVE-2026-75806

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: An established DTLS 1.2 association using an AEAD cipher suite can be terminated by a single unauthenticated datagram whose encrypted fragment is shorter than the mandatory explicit IV and authentication tag overhead.

Impact summary: An attacker who can send a datagram that is routed to an existing DTLS 1.2 association can tear that association down without knowing any key material. This is a Denial of Service limited to the targeted association. There is no memory safety or confidentiality impact.

CWE: CWE-1284: Improper Validation of Specified Quantity in Input

Description: In TLS 1.2 and DTLS 1.2 every record protected by an AEAD cipher suite carries an explicit IV followed by the ciphertext and an authentication tag. When decrypting such a record the record layer passed the record length to the cipher implementation before checking that the record was long enough to contain the explicit IV and the tag. For a record shorter than that overhead the cipher implementation rejected the impossible length, and the record layer treated this as an internal failure and raised a fatal internal_error alert instead of treating the record as one that failed authentication.

In TLS 1.2 the same record causes a fatal internal_error alert instead of the expected bad_record_mac alert. Since any undecryptable record already terminates a TLS connection, this is a protocol conformance issue rather than a security issue in TLS.

The fix validates the record length against the explicit IV and tag length before any AEAD processing, so that TLS reports bad_record_mac and DTLS silently discards the record.

FIPS impact: no The affected code is outside the FIPS module boundary.

Remediation

There is no fixed version for Debian:12 openssl.

References

low severity
new

CVE-2026-77696

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: SM2 signature generation uses non-constant-time arithmetic on secret values, forming a timing side-channel.

Impact summary: An attacker able to measure SM2 signing times may learn information about the per-signature secret nonce, which over many signatures can, via a lattice / Hidden Number Problem attack, lead to recovery of the private key.

CWE: CWE-208: Observable Timing Discrepancy

Description: SM2 signature generation computes the signature value using variable-time BIGNUM operations on the secret nonce and the private key, so the time taken to produce an SM2 signature depends on these secret values, forming a timing side-channel.

Applications performing SM2 signature generation are affected on all platforms.

FIPS Impact: no SM2 is not a FIPS algorithm.

Remediation

There is no fixed version for Debian:12 openssl.

References

low severity
new

CVE-2026-84782

  • Vulnerable module: openssl
  • Introduced through: openssl@3.0.20-1~deb12u2, openssl/libssl-dev@3.0.20-1~deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › openssl@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl-dev@3.0.20-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › openssl/libssl3@3.0.20-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream openssl package and not the openssl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Issue summary: The DTLS retransmission logic does not correctly handle a handshake message write that is suspended part-way through. The retransmitted message can be read past the message buffer and the retransmission overwrites the internal state the suspended write needs to resume correctly.

Impact summary: The retransmitted message can disclose a heap memory to the peer as plaintext handshake data or cause a crash and a Denial of Service when the read reaches an unmapped memory region.

CWE: CWE-125: Out-of-bounds Read

Description: DTLS handshake messages can be written out in multiple fragments, and a write can suspend mid-message (returning WANT_WRITE) if the underlying transport temporarily cannot accept more data. While such a write is suspended, the DTLS retransmission timer may independently fire and ask the retransmission logic to resend an earlier, already-acknowledged-as-sent message from its retransmit queue.

The retransmission logic reused the same internal buffer and position tracking as the message that was still being written, without resetting the position back to the start of the message being retransmitted. As a result the retransmission was read starting from wherever the suspended write had left off, producing a mislabelled message whose body was leftover bytes from the other, larger message still in flight - content that was never meant to be sent at that point, and which could run past the end of the allocated buffer.

Separately, even when the retransmission is positioned correctly, allowing it to run to completion while another write is suspended overwrites the same shared bookkeeping that the suspended write depends on to resume. When the application later resumes the suspended write (via a subsequent SSL_read(), SSL_write(), SSL_accept(), or SSL_connect() call), it finds that bookkeeping in a state inconsistent with the message and aborts the process in a debugging build.

The fix resets the retransmission's read position to the start of the message before resending, and skips retransmission entirely whenever a handshake write is still suspended, deferring to the next call that resumes it instead.

FIPS impact: no The affected code is outside the FIPS module boundary.

Remediation

There is no fixed version for Debian:12 openssl.

References

low severity

CVE-2026-54411

  • Vulnerable module: pam/libpam-modules
  • Introduced through: pam/libpam-modules@1.5.2-6+deb12u2, pam/libpam-modules-bin@1.5.2-6+deb12u2 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › pam/libpam-modules@1.5.2-6+deb12u2
  • Introduced through: buildpack-deps@bookworm › pam/libpam-modules-bin@1.5.2-6+deb12u2
  • Introduced through: buildpack-deps@bookworm › pam/libpam-runtime@1.5.2-6+deb12u2
  • Introduced through: buildpack-deps@bookworm › pam/libpam0g@1.5.2-6+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream pam package and not the pam package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or network-adjacent attacker able to repeatedly drive authentication through a calling service to recover the plaintext password of a target account by measuring response-timing differences.

Remediation

There is no fixed version for Debian:12 pam.

References

low severity

Loop with Unreachable Exit Condition ('Infinite Loop')

  • Vulnerable module: patch
  • Introduced through: patch@2.7.6-7

Detailed paths

  • Introduced through: buildpack-deps@bookworm › patch@2.7.6-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream patch package and not the patch package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination.

This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9

Remediation

There is no fixed version for Debian:12 patch.

References

low severity

NULL Pointer Dereference

  • Vulnerable module: patch
  • Introduced through: patch@2.7.6-7

Detailed paths

  • Introduced through: buildpack-deps@bookworm › patch@2.7.6-7

NVD Description

Note: Versions mentioned in the description apply only to the upstream patch package and not the patch package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility to crash and resulting in a denial of service.

This issue has been fixed in the commit e6d6a4e021660679d7fc9150f981d4920f722313

Remediation

There is no fixed version for Debian:12 patch.

References

low severity

CVE-2025-15649

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.

_dosToUnixTime() decodes the local-file-header last-modification date field and calls Time::Local::timelocal() without an eval guard. A header whose date field decodes to an out-of-range month, day, or hour causes timelocal() to die.

The exception propagates out of IO::Uncompress::Unzip->new($file) where callers expect undef plus $UnzipError.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-12087

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Socket versions before 2.041 for Perl have an out-of-bounds heap read.

In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is read, so the check tests the byte length carried over from the preceding multiaddr argument instead. Both addresses occupy a 4-byte field, so a valid multiaddr lets a source of any length pass the check, and the source is then copied into the 4-byte imr_sourceaddr field with a fixed-size copy. A source shorter than 4 bytes is not rejected, and the copy reads up to 3 bytes past the end of its buffer.

Calling pack_ip_mreq_source() with a source value shorter than 4 bytes copies adjacent heap memory into the returned packed structure.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-15534

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Perl versions through 5.45.1 have out-of-bounds heap reads and writes during regular expression matching via an undersized superlinear cache in S_regmatch.

The regex engine's superlinear cache holds one bit per subject position for each participating WHILEM node, so the bit count is the subject length plus one times the number of nodes. Nothing checks that product for positive overflow of the signed 32-bit count: a 286331153 byte subject matched against a pattern with 15 participating nodes stores the count as 14, leaving a two byte cache. The cache is then indexed from the real match position and node number, so reads go past the end of the allocation, and on failure CACHEsayNO sets a bit past it.

A caller that matches an attacker controlled subject of this size against a pattern of this shape can crash the process or corrupt heap memory.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-19487

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan early in S_find_byclass.

The prescan walks the subject for positions where the full pattern could match, and the engine tries it from the leftmost one recorded. A failing transition sets the failed flag, and a later successful transition does not clear it, so the prescan reads the stale flag as a failure and stops before it can record a candidate that starts earlier. It takes a subject where one candidate is recorded and a later character then forces a fallback through a fail link that succeeds.

Example:

"ABCDE" =~ m/ABCF|BCDE|C/; # matches C at offset 2, not BCDE "ABCDE" =~ m/ABCF|BCDE|C(G)/; # no match, BCDE missed

An alternation like this can miss input it should match, or match it on the wrong branch, so an access or filtering decision made from the result can be wrong.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-48959

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.

fastForward() compares length $offset (the digit count of the offset, 1 to 19) against the chunk size $c instead of $offset itself, so $c shrinks from 16 KiB to 1-19 bytes per iteration.

Extracting a named entry from an attacker supplied zip via IO::Uncompress::Unzip->new($zip, Name => $target) drives a per-byte read loop scaling with the entry's compressed size, up to the non-Zip64 4 GiB cap.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-48962

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob.

_parseOutputGlob() wraps the caller-supplied output glob string in double quotes and stores it in the parser state; _getFiles() then runs the stored expression through eval STRING. A literal double quote in the output glob closes the dquote wrapper, and the characters that follow are evaluated as Perl.

Arbitrary Perl in the output glob executes at the calling process's privilege.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-57433

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record.

retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value.

A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-7010

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.

The unvalidated inputs are the method and URI in the request line, the URL host that becomes the Host: header, and HTTP/1.1 control data field values.

An attacker who controls one of these inputs, for example a user supplied URL passed to a webhook or URL fetch endpoint, can inject additional headers and smuggle requests to the upstream server.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2026-7017

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

This vulnerability has not been analyzed by NVD yet.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity
new

CVE-2026-82560

  • Vulnerable module: perl
  • Introduced through: perl@5.36.0-7+deb12u3, perl/libperl5.36@5.36.0-7+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › perl@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/libperl5.36@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-base@5.36.0-7+deb12u3
  • Introduced through: buildpack-deps@bookworm › perl/perl-modules-5.36@5.36.0-7+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream perl package and not the perl package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting drives the margin to the output width.

Each =over adds its indent to the margin, which wrap() subtracts from the output width to get the space available for text. When that space reaches zero, the line-splitting substitution matches the empty string, and the loop consumes no input while appending the margin padding on every pass.

Formatting an attacker-supplied POD document never returns, and the output grows until memory is exhausted.

Remediation

There is no fixed version for Debian:12 perl.

References

low severity

CVE-2025-15366

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The imaplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2025-15367

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The poplib module, when passed a user-controlled command, can have additional commands injected using newlines. Mitigation rejects commands containing control characters.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-11940

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself.  The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory.  This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-11972

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-12003

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree.

On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '....', which results in a landmark of '....\Modules\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative Lib folder that will be discovered by an otherwise restricted install.

Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive.

Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new Python install manager to install for the current user. Installs where the directory two levels above the Python installation directory have equivalent permissions are unaffected (in general, a per-user install cannot be modified at all by other users, removing any escalation of privilege risk, and could be directly modified by a privileged user, making the potential tampering irrelevant). Alternative mitigations might include preemptively creating and restricting access to a Modules directory. Be aware that only 3.13 and 3.14 will receive updated legacy installers - earlier fixes are only provided as sources.

Platforms other than Windows allow VPATH to be overridden, but as they don't usually use a separated directory in the build for binaries, are unlikely to have a landmark reference outside of the install directory.

The landmark detection involving VPATH is a fallback for when a more specific landmark - .\pybuilddir.txt - is absent, and was included for compatibility. Future releases of Python will no longer include the fallback, and so builds will need to generate or preserve the pybuilddir.txt file in order to work in-tree. This landmark file has been generated on Windows since 3.11, and on other platforms for longer.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity
new

CVE-2026-12345

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The cleanup of tempfile.TemporaryDirectory is vulnerable to a race condition. An attacker who can modify the tree during cleanup can replace a directory with a symbolic link, causing files outside of the temporary directory to be deleted or have their permissions and file flags reset, with the privileges of the process performing the cleanup. Note that platforms where shutil.rmtree.avoids_symlink_attacks is false, remain affected, and file flags may still be reset outside of the tree on all platforms.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-1502

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

CR/LF bytes were not rejected by HTTP client proxy tunnel headers or host.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-15310

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When decompressing crafted zip files using the bzip/LZMA/Zstandard

compressions, Python could use an attacker-controlled size to

pre-allocate memory, possibly resulting in memory exhaustion.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-15806

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, did not take the URL scheme into account when matching stored credentials against a requested URL. Credentials added for an https:// URL were also used for requests to the same host over http://, so an attacker able to redirect or downgrade a client to plain HTTP (for example, via an HTTPS-to-HTTP redirect or an on-path position) could capture credentials in cleartext. Credentials added for http:// URLs could likewise be sent over https://.

Credential matching is now scoped by URL scheme. Credentials registered with a URL that includes a scheme are only used for requests with the same scheme. Credentials registered with a bare authority (such as example.com or example.com:8080) continue to match any scheme, preserving compatibility with existing code, including proxy authentication.

Users who cannot upgrade immediately can mitigate by ensuring that applications never make plain http:// requests to hosts for which credentials are registered, for example by not following redirects to http:// URLs.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-17084

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The "stringprep" module didn't process characters from RFC 3454 tables B.2 or B.3 correctly: the latest Unicode codepoint attributes were used instead of the specified Unicode 3.2.0. This behavior would cause mismatches when processing domain names using IDNA 2003 (the "idna" codec) and the in_table_b2() function of the "stringprep" module. This only affects domain names containing characters that were not previously registered or had their Unicode attributes such as case-folding behavior updated since Unicode 3.2.0.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-18503

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Attacker-controlled CSV samples can trigger super-linear regular-expression work during dialect sniffing and consume significant CPU when applications pass unbounded input to csv.Sniffer.sniff().

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-3276

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. This affects all normalization forms.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-3446

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

When calling base64.b64decode() or related functions the decoding process would stop after encountering the first padded quad regardless of whether there was more information to be processed. This can lead to data being accepted which may be processed differently by other implementations. Use "validate=True" to enable stricter processing of base64 data.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-3479

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

DISPUTED: The project has clarified that the documentation was incorrect, and that pkgutil.get_data() has the same security model as open(). The documentation has been updated to clarify this point. There is no vulnerability in the function if following the intended security model.

pkgutil.get_data() did not validate the resource argument as documented, allowing path traversals.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-6879

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Element.findall() and fully-consumed Element.iterfind() exhibit O(n^2) time complexity when using XPath index predicates (e.g. [1], [last()], [last()-N]) on XML documents with many same-tag siblings. Element.find() is only affected when the first match is near the end  of the sibling list, such as with [last()] or [last()-N];  .//item[1] short-circuits after the first match.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-8328

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to replace server-supplied PASV host addresses with the actual peer address (getpeername()[0]), ftpcp() still calls parse227() directly and passes the raw attacker-controllable IP address and port to target.sendport(). This patch is related to CVE-2021-4189.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2026-9669

  • Vulnerable module: python3.11
  • Introduced through: python3.11@3.11.2-6+deb12u8, python3.11/libpython3.11-minimal@3.11.2-6+deb12u8 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › python3.11@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-minimal@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/libpython3.11-stdlib@3.11.2-6+deb12u8
  • Introduced through: buildpack-deps@bookworm › python3.11/python3.11-minimal@3.11.2-6+deb12u8

NVD Description

Note: Versions mentioned in the description apply only to the upstream python3.11 package and not the python3.11 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompressor to resume from an invalid internal state and perform out-of-bounds writes to a stack buffer. This could crash the process when processing untrusted data.

Remediation

There is no fixed version for Debian:12 python3.11.

References

low severity

CVE-2024-56433

  • Vulnerable module: shadow/login
  • Introduced through: shadow/login@1:4.13+dfsg1-1+deb12u2 and shadow/passwd@1:4.13+dfsg1-1+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › shadow/login@1:4.13+dfsg1-1+deb12u2
  • Introduced through: buildpack-deps@bookworm › shadow/passwd@1:4.13+dfsg1-1+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream shadow package and not the shadow package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.

Remediation

There is no fixed version for Debian:12 shadow.

References

low severity

CVE-2025-70873

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An information disclosure issue in the zipfileInflate function in the zipfile extension in SQLite v3.51.1 and earlier allows attackers to obtain heap memory via supplying a crafted ZIP file.

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

CVE-2025-7709

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of tombstone pointers is calculated and truncated into a 32-bit integer. A pointer to partially controlled data can then be written out of bounds.

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

CVE-2026-50812

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a denial of service. The issue occurs when sqlite3changeset_apply_v3() applies a corrupt changeset and reaches sqlite3_value_type() with a NULL sqlite3_value pointer.

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

CVE-2026-50813

  • Vulnerable module: sqlite3/libsqlite3-0
  • Introduced through: sqlite3/libsqlite3-0@3.40.1-2+deb12u2 and sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-0@3.40.1-2+deb12u2
  • Introduced through: buildpack-deps@bookworm › sqlite3/libsqlite3-dev@3.40.1-2+deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream sqlite3 package and not the sqlite3 package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the Session Extension changeset concat/changegroup merge path

Remediation

There is no fixed version for Debian:12 sqlite3.

References

low severity

CVE-2026-15059

  • Vulnerable module: systemd/libsystemd0
  • Introduced through: systemd/libsystemd0@252.39-1~deb12u2 and systemd/libudev1@252.39-1~deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › systemd/libsystemd0@252.39-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › systemd/libudev1@252.39-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream systemd package and not the systemd package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation.

Remediation

There is no fixed version for Debian:12 systemd.

References

low severity

CVE-2026-16742

  • Vulnerable module: systemd/libsystemd0
  • Introduced through: systemd/libsystemd0@252.39-1~deb12u2 and systemd/libudev1@252.39-1~deb12u2

Detailed paths

  • Introduced through: buildpack-deps@bookworm › systemd/libsystemd0@252.39-1~deb12u2
  • Introduced through: buildpack-deps@bookworm › systemd/libudev1@252.39-1~deb12u2

NVD Description

Note: Versions mentioned in the description apply only to the upstream systemd package and not the systemd package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user

Remediation

There is no fixed version for Debian:12 systemd.

References

low severity

CVE-2026-36849

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

This vulnerability has not been analyzed by NVD yet.

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

CVE-2026-52490

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

CVE-2026-52491

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtiff/tools/thumbnail.c: main() component

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

CVE-2026-52492

  • Vulnerable module: tiff/libtiff-dev
  • Introduced through: tiff/libtiff-dev@4.5.0-6+deb12u4, tiff/libtiff6@4.5.0-6+deb12u4 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › tiff/libtiff-dev@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiff6@4.5.0-6+deb12u4
  • Introduced through: buildpack-deps@bookworm › tiff/libtiffxx6@4.5.0-6+deb12u4

NVD Description

Note: Versions mentioned in the description apply only to the upstream tiff package and not the tiff package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

An integer overflow in the libtiff rgb2ycbcr utility's cvtRaster() function when computing strip buffer sizes can result in an undersized heap allocation and subsequent heap-based buffer overflow during YCbCr conversion of a crafted TIFF image

Remediation

There is no fixed version for Debian:12 tiff.

References

low severity

CVE-2026-53613

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

This vulnerability has not been analyzed by NVD yet.

Remediation

There is no fixed version for Debian:12 util-linux.

References

low severity

CVE-2026-53615

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

This vulnerability has not been analyzed by NVD yet.

Remediation

There is no fixed version for Debian:12 util-linux.

References

low severity

Time-of-check Time-of-use (TOCTOU)

  • Vulnerable module: util-linux
  • Introduced through: util-linux@2.38.1-5+deb12u3, util-linux/bsdutils@1:2.38.1-5+deb12u3 and others

Detailed paths

  • Introduced through: buildpack-deps@bookworm › util-linux@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/bsdutils@1:2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libblkid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount-dev@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libmount1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libsmartcols1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/libuuid1@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/mount@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/util-linux-extra@2.38.1-5+deb12u3
  • Introduced through: buildpack-deps@bookworm › util-linux/uuid-dev@2.38.1-5+deb12u3

NVD Description

Note: Versions mentioned in the description apply only to the upstream util-linux package and not the util-linux package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when setting up loop devices, validates the source file path with user privileges via fork() + setuid() + realpath(), but subsequently re-canonicalizes and opens it with root privileges (euid=0) without verifying that the path has not been replaced between both operations. Neither O_NOFOLLOW, nor inode comparison, nor post-open fstat() are employed. This allows a local unprivileged user to replace the source file with a symlink pointing to any root-owned file or device during the race window, causing the SUID binary to open and mount it as root. Exploitation requires an /etc/fstab entry with user,loop options whose path points to a directory where the attacker has write permission, and that /usr/bin/mount has the SUID bit set (the default configuration on virtually all Linux distributions). The impact is unauthorized read access to root-protected files and block devices, including backup images, disk volumes, and any file containing a valid filesystem. This issue has been patched in version 2.41.4.

Remediation

There is no fixed version for Debian:12 util-linux.

References

low severity

CVE-2026-15146

  • Vulnerable module: wget
  • Introduced through: wget@1.21.3-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › wget@1.21.3-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream wget package and not the wget package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.

Remediation

There is no fixed version for Debian:12 wget.

References

low severity

CVE-2026-58471

  • Vulnerable module: wget
  • Introduced through: wget@1.21.3-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › wget@1.21.3-1+deb12u1

NVD Description

This vulnerability has not been analyzed by NVD yet.

Remediation

There is no fixed version for Debian:12 wget.

References

low severity

Server-Side Request Forgery (SSRF)

  • Vulnerable module: wget
  • Introduced through: wget@1.21.3-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › wget@1.21.3-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream wget package and not the wget package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

Applications that use Wget to access a remote resource using shorthand URLs and pass arbitrary user credentials in the URL are vulnerable. In these cases attackers can enter crafted credentials which will cause Wget to access an arbitrary host.

Remediation

There is no fixed version for Debian:12 wget.

References

low severity

Unchecked Input for Loop Condition

  • Vulnerable module: wget
  • Introduced through: wget@1.21.3-1+deb12u1

Detailed paths

  • Introduced through: buildpack-deps@bookworm › wget@1.21.3-1+deb12u1

NVD Description

Note: Versions mentioned in the description apply only to the upstream wget package and not the wget package as distributed by Debian. See How to fix? for Debian:12 relevant fixed versions and status.

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequence number from the FTP challenge line is used as an iteration count for an MD5 key-derivation loop without any upper bound validation. A malicious FTP server or a network attacker positioned to intercept FTP traffic can send a crafted OPIE challenge with a sequence number near INT_MAX, causing wget to perform up to approximately 2.1 billion MD5 computations and suspend for some time. The --timeout option does not mitigate this because it applies only to network I/O, not CPU computation.

This issue was fixed in commit e9697d98e7249b0f68a6be040a4f3dcc5bc101fa

Remediation

There is no fixed version for Debian:12 wget.

References