- Package:
- src:bettercap
- Source:
- src:bettercap
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-15 12:49:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for bettercap. CVE-2026-8275[0]: | A vulnerability was detected in bettercap up to 2.41.5. Affected by | this vulnerability is the function ippReadChunkedBody of the file | modules/zerogod/zerogod_ipp_primitives.go of the component zerogod | IPP Service. Performing a manipulation results in integer coercion | error. The attack can be initiated remotely. The attack is | considered to have high complexity. The exploitation appears to be | difficult. The exploit is now public and may be used. The patch is | named 3731d5576cffae9eefe3721cd46a40933304129f. To fix this issue, | it is recommended to deploy a patch. CVE-2026-8276[1]: | A flaw has been found in bettercap up to 2.41.5. Affected by this | issue is some unknown functionality of the file | modules/mysql_server/mysql_server.go of the component MySQL Server. | Executing a manipulation can lead to integer coercion error. The | attack can be launched remotely. The attack requires a high level of | complexity. The exploitation is known to be difficult. The exploit | has been published and may be used. This patch is called | 0eaa375c5e5446bfba94a290eff92967a5deac9e. It is advisable to | implement a patch to correct this issue. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-8275 https://www.cve.org/CVERecord?id=CVE-2026-8275 [1] https://security-tracker.debian.org/tracker/CVE-2026-8276 https://www.cve.org/CVERecord?id=CVE-2026-8276 Regards, Salvatore
Hello, Bug #1136448 in bettercap reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/pkg-security-team/bettercap/-/commit/0df58045cd294e871fd3227526ac79997410ca00 ------------------------------------------------------------------------ Add debian/patches/CVE-2026-8276.patch (Closes: #1136448, CVE-2026-8276) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1136448
Hello Salvatore Bonaccorso, The vulnerability is located in the "zerogod" module. However, this module was introduced later in commit "51a5b4ad6ea917d40f92861fbc1afcfa5a9af6bb" (Thu Sep 19 21:49:02 2024 +0200): https://github.com/bettercap/bettercap/commit/51a5b4ad6ea917d40f92861fbc1afcfa5a9af6bb Our package is based on the bettercap v2.33.0 release, corresponding to commit "9937e797ae40a418ec40836d306af04beff017a4" (Fri Aug 9 11:25:32 2024 +0200): https://github.com/bettercap/bettercap/commit/9937e797ae40a418ec40836d306af04beff017a4 This commit predates the introduction of the "zerogod" module. As a result, the vulnerable code is not present in the version we package. Therefore, I believe this CVE is not applicable to our package. This bug has already been addressed in our package. We have applied the corresponding patch in our packaging as commit 0df58045cd294e871fd3227526ac79997410ca00 in Salsa. Regards
We believe that the bug you reported is fixed in the latest version of
bettercap, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1136448@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Francisco Vilmar Cardoso Ruviaro <vilmar@debian.org> (supplier of updated bettercap package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 10 Jul 2026 02:33:50 +0000
Source: bettercap
Architecture: source
Version: 2.33.0-3
Distribution: unstable
Urgency: medium
Maintainer: Francisco Vilmar Cardoso Ruviaro <vilmar@debian.org>
Changed-By: Francisco Vilmar Cardoso Ruviaro <vilmar@debian.org>
Closes: 1136448
Changes:
bettercap (2.33.0-3) unstable; urgency=medium
.
* Add debian/patches/CVE-2026-8276.patch.
(Closes: #1136448, CVE-2026-8276)
Checksums-Sha1:
39b3ca5b906c20af2388bdf157c35b08d9eb3988 3504 bettercap_2.33.0-3.dsc
63e29b0bdad5df93fd538a9946e79d62203f9464 6996 bettercap_2.33.0-3.debian.tar.xz
f0f81010eb3de9a2efd0b1f6bc0fe26839d2ae18 10585 bettercap_2.33.0-3_amd64.buildinfo
Checksums-Sha256:
849421eebe40d12787a3fc5d7296b9c3b43515c7790801d90ee3011f1835500c 3504 bettercap_2.33.0-3.dsc
3acbfa4ecef064f41d5c91d239dbf6f70493ddb69e166ad8a34c5fbb62ebd237 6996 bettercap_2.33.0-3.debian.tar.xz
fcb3060a05e1c8fc21a0feb8174225c765f5da226a57c21538a728e5330ca6e6 10585 bettercap_2.33.0-3_amd64.buildinfo
Files:
f0263d9a59d05d0672ee0a1ca87a4fa1 3504 net optional bettercap_2.33.0-3.dsc
b10d95167b369b4c369755dbe1fde29b 6996 net optional bettercap_2.33.0-3.debian.tar.xz
9e8b126e19090b9e7eda16c052bab51e 10585 net optional bettercap_2.33.0-3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEEG4z2Vu87hEcvSPDngvv3BgsvfQAFAmpQYFcSHHZpbG1hckBk
ZWJpYW4ub3JnAAoJEIL79wYLL30A3XAQAIqZxHGczghdHEs7F89CG3Bk9osZAtb9
Uys6ZSf3ud0Xb4kfugTrl2BcKNF5Q4WdLTR0efdzbQN9YYsV3HqrAXv5bRod9xBG
YOj/BJ1ruxLkBNmHFamtYzopcRfRSMAkG61NerktnsAFsIh9JFL/1WOu605Cy6qJ
DqHNQIYOw1TknHrRLS2sacXdLT3oaJeBYNxilvCA2ag58RDhdgUY3ZB9SbXOEU7P
50w2UpcZMnl2RCnlwkD9GIGxyBsOSOtOamgWR1A+rZAiaK77cgvAvvm163iTzUcI
ERVtXRCGC59ziQobcWUgd4nXR3VU+roJASU8SY820tMvLXJzm5630pq0MluxDcSm
J2qYZNdzfnH6EPbV6U+jA6ionsgOBV4YwJL4lUR5zJhhSW58PayzUBhQ1dDBdDOX
wl/t3Gwb3XRPF0AATGniim1qttLH5ygEvxay8wWQUfply2vcj0791+0tgZJiT76B
ZxI3wfzVSJwdaKHAmFoQZZKY0l85yOCOe9wdVXYYejW/Y3kRgQSs7nuYBwD32Ht3
vsh8fHO+a9w4TVA4ahmwxEUyXtnlzJJ6uU0mxfGeynM2psUgyyX4A0g13VgOlZZu
VM0MCHiXwev3rqZ/Nua+aFJXYc7JpXxizpoajS9crWRe8+/hBojhL1I4htu5ARo6
CFY+uXFhOP1F
=69dO
-----END PGP SIGNATURE-----
Hi Francisco, Thanks a lot for the analysis. I have updated the security-tracker information. Thanks! FWIW, the issue does not warrrant a DSA, but if you have spare cycles, this might be fixed in a upcoming point release. In any case we marked the issue already as no-dsa. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
bettercap, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1136448@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Francisco Vilmar Cardoso Ruviaro <vilmar@debian.org> (supplier of updated bettercap package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 13 Jul 2026 02:41:40 +0000
Source: bettercap
Architecture: source
Version: 2.33.0-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian Security Tools <team+pkg-security@tracker.debian.org>
Changed-By: Francisco Vilmar Cardoso Ruviaro <vilmar@debian.org>
Closes: 1136448
Changes:
bettercap (2.33.0-1+deb13u1) trixie; urgency=medium
.
* Add debian/patches/CVE-2026-8276.patch.
(Closes: #1136448, CVE-2026-8276)
Checksums-Sha1:
258f538b272b0dc5ed242b94bdd95ab6e6cb5660 3536 bettercap_2.33.0-1+deb13u1.dsc
d5f31cbc19ab3a8eb645c04557687f791f3add24 6356 bettercap_2.33.0-1+deb13u1.debian.tar.xz
94b0225a253ea34278d24d2fb61b57e95ae27334 10437 bettercap_2.33.0-1+deb13u1_amd64.buildinfo
Checksums-Sha256:
43a0c1ab70c4f27886cd10c75d911c9861bbf3264266ca0ef2277dde7fd0c024 3536 bettercap_2.33.0-1+deb13u1.dsc
9ec244d348040ed1c782176f81374ed2d1ad34defee626ef82df4546e98e7039 6356 bettercap_2.33.0-1+deb13u1.debian.tar.xz
3589515022b649fc62610126185b3c4ca149022c92b131a33d147ad7a8c96679 10437 bettercap_2.33.0-1+deb13u1_amd64.buildinfo
Files:
724999f1919741b6196e07480f8ef8bb 3536 net optional bettercap_2.33.0-1+deb13u1.dsc
b9d44ab61fc5ee717b0730f173ddb613 6356 net optional bettercap_2.33.0-1+deb13u1.debian.tar.xz
a20b3925db0e9203deb574c5523a9d27 10437 net optional bettercap_2.33.0-1+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJGBAEBCgAwFiEEG4z2Vu87hEcvSPDngvv3BgsvfQAFAmpUVEsSHHZpbG1hckBk
ZWJpYW4ub3JnAAoJEIL79wYLL30A00QP/1Aata5tlZNXKSsDSdbnZOXkiz4NE4xu
S9s9VHcrBMi3jwQPKpImYN4IKEOLa5NdXaDv0Ag6ICw4G2TqgKRIybyqufXXZGZc
lIjV5tZdiCPfoJwybgFcQX3lTVEjwHpcaaUxiJQ4ONPqyMmFm9mdGtAzqFRoVm3F
LTLpxjHqTmXg23wJhEoda7MiouqXDjkkKSE2cyY/oD6DnxMMSs8VGzNesf2IKWdC
FW80AO4bHXlGiOG4nv6gyakNC0ObEvI3Gk19AMAVY77bgLMBPH9gIDZeoZBM2T7m
ubBTJI3nfORMNIVm35Eo99MQ5bDT+sebhzZkn2ZOsRkAtMfVClKxESZVXr16zt+T
wB9TIbcBviTYLSjFluOhq2pSasdNTbs6gIUffq8bseAzc6kR0PU5gQZq9t4sL449
DlR1GSqjeUB+I5Z1FlhPNUNVQ0fip/n8h+lHrCU9ngJ/nMtwO4yADSkU6rOZ+5hI
7WRYMWQbSl5s+PW5rt1k162QcCO+7P3O91ecqOjxkulnH0yDr8ZphSEdor6w6CB6
ecsEu0uh+6ipgqxEfxgowBrycJw5rtFnFW7uWgbV76DDsJgC5X8Uc+cHEsDiecBW
psBTz7KKg8+DOC9XdonhaDaS4JnfvAAjhHvl/QtfpYK0O0eLmwiWYCbIChuofCTM
WrRu2aEZSsfn
=lOMQ
-----END PGP SIGNATURE-----