- Package:
- src:openslide
- Source:
- src:openslide
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-06-30 18:19:14 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for openslide. CVE-2026-48977[0]: | Arbitrary memory write with crafted Ventana BIF file If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-48977 https://www.cve.org/CVERecord?id=CVE-2026-48977 [1] https://github.com/openslide/openslide/security/advisories/GHSA-mxg2-48g7-fmwc Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hello, Bug #1140003 in openslide reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/med-team/openslide/-/commit/8a5f43bf436e26fb8fe85552965e8faa52ccdf6a The change lacks attempt to apply the test case, because the binary representation of a newly introduced test file is not possible in the patch. Closes: #1140003 ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140003
On 3.4.1 if you return NULL you'll leak all kinds of stuff. You should goto FAIL instead, matching the other error paths in that function.
Hi Benjamin, Benjamin Gilbert, on 2026-06-14: Acknowledged and fixing that immediately. Thank you, :)
We believe that the bug you reported is fixed in the latest version of
openslide, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1140003@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Étienne Mollier <emollier@debian.org> (supplier of updated openslide package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 14 Jun 2026 18:20:29 +0200
Source: openslide
Architecture: source
Version: 3.4.1+dfsg-8
Distribution: unstable
Urgency: medium
Maintainer: Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Changed-By: Étienne Mollier <emollier@debian.org>
Closes: 1140003
Changes:
openslide (3.4.1+dfsg-8) unstable; urgency=medium
.
* Team upload.
* CVE-2026-48977.patch: new: fix CVE-2026-48977.
The change lacks attempt to apply the test case, because the binary
representation of a newly introduced test file is not possible in the
patch. (Closes: #1140003)
* d/control: drop redundant Rules-Requires-Root: no.
* d/control: drop redundant Priority: optional.
* d/control: declare compliance to standards version 4.7.4.
* d/watch: convert to watch file version 5.
* d/copyright: drop the old FSF mail address.
Checksums-Sha1:
9ec2e3810e282cb5ca9ab740cf5b323501b2c458 2714 openslide_3.4.1+dfsg-8.dsc
965948055c4f8399ed4870ecd427ed3db4cfeb53 20440 openslide_3.4.1+dfsg-8.debian.tar.xz
Checksums-Sha256:
2f1dda6b53c7673848498c32ca3e72d1f8206dfbbec728e8824409e161c7a157 2714 openslide_3.4.1+dfsg-8.dsc
6c374bde4bd7c8d3b9650de8522959c87ea2b85246df1e8042818447518a9fd9 20440 openslide_3.4.1+dfsg-8.debian.tar.xz
Files:
a156533cbefd7c69622c394c67c108ea 2714 libs optional openslide_3.4.1+dfsg-8.dsc
7686bb2ea621bb291a807aaf41cc27c1 20440 libs optional openslide_3.4.1+dfsg-8.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEEj5GyJ8fW8rGUjII2eTz2fo8NEdoFAmou1nEUHGVtb2xsaWVy
QGRlYmlhbi5vcmcACgkQeTz2fo8NEdqPXA/9GmA5Glcp3U+D0DeE4CHk8YJ0QnE+
Z83Am0I7wYqHtxlOpDFHZs7I3tdO45Aq1quC0XwAIuwfiB8kV69QW73BO9AyWyW3
qn0mTaMB3/J4/g+CeZyaqsYrvjeFTMXJlhruy6iMNhsvcyiEmfdsj/XiysY6L8io
RX4bo6QPEKQyg5pPruEhup3RI1RgYAgfsQxE10mqmen7EEFVDUVSbLYKIEbb7KBD
Vhq2H7/egLkUDuGGFp/aZGhBYpo/9Mtzln+42XxgqgCNjqjyu3izLVRtSToNwgtR
cD/fku94LCSKQ9/1FcqzPE7Eb4f8y5tGH6KqZkvZw+vJIU9fglw0FfTkovjY6JNF
z/MvHcC6FU969YNt8ELevdeeZ3wLDF84V6zCbJ2gY/7TSsaW0X+1MRNwGr102Uex
e0eJ+ORT8kXv7+7nm5MUWxf/0A308eXKXbAKFgkcKc+4U0eBn7eCUFtbRdsMrj2q
5VQ4gBVgKQSrX2XTQp8TQ805ol4o8dvpX9QDsoDkmfLLkkLgw1Ah7rr1AOzCn89n
6J4dj9Cs5f1aOqpYVhmGhb+ONo95k1zcOXQOSVoM+FiRWJTEhgRDw1eoxcPi2Ikd
bc3huTnVoC7mdiEpnVXa64ZStaqr7sSv+GbHyJGoL1MH2u9Of0SznzCB40huvoaW
agOFay94Qh7lh+E=
=exLs
-----END PGP SIGNATURE-----
Control: found -1 3.4.1+dfsg-6 Control: fixed -1 3.4.1+dfsg-9 Hi Salvatore and the Security Team, Thank you for the notification, the fix (hopefully correct this time) should make it to Debian unstable soon, and then forky in a couple of days. I have proceeded to an urgency=high upload of openslide 3.4.1+dfsg-9 this time. I saw preparatory work for a version 4.0.0 in Salsa, but that was unfinished work and I was unsure of the blockers, so I favored a targeted fix for now. trixie and bookworm are running the same 3.4.1 upstream version (3.4.1+dfsg-7 and 3.4.1+dfsg-6 packaging iterations respectively), so I have begun wrapping up an eventual security upload for stable and oldstable. You will find the debdiffs in attachment. I have problems testing the fix for myself. The test suite in the package currently does not trigger, in addition to issues with inlining binaries in quilt patches. This is how I tripped on the carpet with the return NULL vs goto FAIL in the patch. Otherwise, I assume this would have been caught by the test case added along upstream commit 2be88bd. :( Thankfully, as you might have witnessed, upstream has been very reactive to pinpoint issues and provide proper corrections. :) I have reviewed the way the function parse_level0_xml evolved between 3.4.1 and 4.0.0 and I agree that the correction was needed. With these elements, should I go ahead with upload to trixie-security and to bookworm-security? Have a nice day, :)
Control: found -1 3.4.1+dfsg-6 Control: fixed -1 3.4.1+dfsg-9 Hi Salvatore and the Security Team, Thank you for the notification, the fix (hopefully correct this time) should make it to Debian unstable soon, and then forky in a couple of days. I have proceeded to an urgency=high upload of openslide 3.4.1+dfsg-9 this time. I saw preparatory work for a version 4.0.0 in Salsa, but that was unfinished work and I was unsure of the blockers, so I favored a targeted fix for now. trixie and bookworm are running the same 3.4.1 upstream version (3.4.1+dfsg-7 and 3.4.1+dfsg-6 packaging iterations respectively), so I have begun wrapping up an eventual security upload for stable and oldstable. You will find the debdiffs in attachment. I have problems testing the fix for myself. The test suite in the package currently does not trigger, in addition to issues with inlining binaries in quilt patches. This is how I tripped on the carpet with the return NULL vs goto FAIL in the patch. Otherwise, I assume this would have been caught by the test case added along upstream commit 2be88bd. :( Thankfully, as you might have witnessed, upstream has been very reactive to pinpoint issues and provide proper corrections. :) I have reviewed the way the function parse_level0_xml evolved between 3.4.1 and 4.0.0 and I agree that the correction was needed. With these elements, should I go ahead with upload to trixie-security and to bookworm-security? Have a nice day, :)
Hello, Bug #1140003 in openslide reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/med-team/openslide/-/commit/ec729c578536ebb3fb165b21c40a1ae3f36fe21a The change lacks attempt to apply the test case, because the binary representation of a newly introduced test file is not possible in the patch. Closes: #1140003 ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140003
Hello, Bug #1140003 in openslide reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/med-team/openslide/-/commit/63446b77227e74be9f9f53a7dfdbc685014e4f9b The change lacks attempt to apply the test case, because the binary representation of a newly introduced test file is not possible in the patch. Closes: #1140003 ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140003
Hello, Bug #1140003 in openslide reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/med-team/openslide/-/commit/8a5f43bf436e26fb8fe85552965e8faa52ccdf6a The change lacks attempt to apply the test case, because the binary representation of a newly introduced test file is not possible in the patch. Closes: #1140003 ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140003
Hi Étienne, Sorry for the late followup, there was/is some backlog and openslide was not on topmost on the radar. I still think openslide would be good candidate for the point releases (which are approaching, rather than a dedicated security update). Regards, Salvatore
Hi Salvatore, Salvatore Bonaccorso, on 2026-06-20: No worries, when I saw the multiple security announcements, I've suspected you might be a bit drowned, so I probably should not have insisted to double check the situation. I'm still intending to coordinate with stable release managers and will likely proceed later today. No hard feelings. ;) In the meantime, I've focused on integrating openslide 4.0.1, currently in experimental as it is going to require a transition. Up to version 4.0.0, openslide is affected by CVE-2026-54604 [1]; see also #1099727. Thankfully, if I trust the advisory on Github [2], Debian stable releases are not affected, because they ship with libtiff 4.7.0 or earlier, which do not trigger the vulnerability openslide. [1]: https://security-tracker.debian.org/tracker/CVE-2026-54604 [2]: https://github.com/openslide/openslide/security/advisories/GHSA-f734-jv98-5677 Have a nice day, :)
Hi Étienne, No worries at all, it is manageable, I just think still openslide is better candidate to be batched with other updates in the upcoming point release. It is good if you ask to double check if there are uncertainities (better safe!). Ack we will look on how to update the tracker. Thanks for all your work! Regards, Salvatore
Hi there, Salvatore Bonaccorso, on 2026-06-21: Sounds good! I started the coordination work for upload to proposed-upgrades. It is tracked in #1140493 and #1140494. Thanks for the update! You're welcome, I return the compliment for tracking the security of the system! Have a nice day, :)
We believe that the bug you reported is fixed in the latest version of
openslide, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1140003@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Étienne Mollier <emollier@debian.org> (supplier of updated openslide package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 14 Jun 2026 19:17:44 +0200
Source: openslide
Architecture: source
Version: 3.4.1+dfsg-7+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Changed-By: Étienne Mollier <emollier@debian.org>
Closes: 1140003
Changes:
openslide (3.4.1+dfsg-7+deb13u1) trixie; urgency=medium
.
* CVE-2026-48977.patch: new: fix CVE-2026-48977.
The change lacks attempt to apply the test case, because the binary
representation of a newly introduced test file is not possible in the
patch. (Closes: #1140003)
Checksums-Sha1:
b75028c1e55bb8d671568e816efe47464db56f3d 2754 openslide_3.4.1+dfsg-7+deb13u1.dsc
1026faecb6bdb50ebdd242e1ab25c94091cf0cd0 20368 openslide_3.4.1+dfsg-7+deb13u1.debian.tar.xz
Checksums-Sha256:
c3b25c6ea97ecfcaff5ce28a76586ac1a3239162387b23c3de0b857fa7621650 2754 openslide_3.4.1+dfsg-7+deb13u1.dsc
b9fade4b8151c74315ab72ece5b13fefae39dafc7e6c51c58ebf1f1aa5c8aad2 20368 openslide_3.4.1+dfsg-7+deb13u1.debian.tar.xz
Files:
f7e835e84e8e3dda11f21fd45d5a9d71 2754 libs optional openslide_3.4.1+dfsg-7+deb13u1.dsc
97e259c6293febc2d7a3de7a38d238d6 20368 libs optional openslide_3.4.1+dfsg-7+deb13u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEEj5GyJ8fW8rGUjII2eTz2fo8NEdoFAmpDXoQUHGVtb2xsaWVy
QGRlYmlhbi5vcmcACgkQeTz2fo8NEdrXJw/+PiSO38eadEJrXwm62yREOGPI4FRQ
GlGJWyZWDOdojab5vZOmQh6U6YaD9dFvs+IJWDTMxyNy7wHBddZoLvWhnmNZNjVI
3phY5bDVnZeuocnMfZuZeljc/CNNiJ97+BCYiiDZ2f84/S8TviS8gfWZaVqndk4B
fINn0Lh8GNvtCNiGsV9vcmxhjWoTuIyFqmPMhKV1JvTTMjLbNXfobx37/Hfd7foS
PXDlhnc8sU7diZF46+u4wWVRehqIVgQSLL4mnmIV5II5mjpAZsugsHcsTYNyXiHB
MJgdszRXK/4a3BHhSoXeC2RR+qc61D7EskGHiy65rqoeWL1cE3pOWItEr452Irjj
o0qb1M5UauQHDqnzXfVbMYazeIB0Gc9qmeT0sGeZNbgdSNcAYMvadW+/u5I2iT5u
reguQVeu8L/VIOubdKHi/59ZW3C0NTAXOcjEByycTHhuK9lkODpogS+HDyx8b9Dz
ffybpEYtaNf7Q6osU6lJX8zycM6dsSqd6Uk1xmgh7QR909vD+7CbT2HaECTEfMdm
i5uHkb9kvqSRusgq5/M/kpNXfn3dvPQbFgdPYoJ4JR2/WT3n8znIyTpA/oKyVhVX
oiibFkVw1rg6q7FEntrHQIHj/k9xH65kE27CCj9pVlo2cAHh5E0CKemv12Bfcm7z
gTl9sjHtUuhsiuw=
=1aNZ
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
openslide, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1140003@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Étienne Mollier <emollier@debian.org> (supplier of updated openslide package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 14 Jun 2026 19:52:57 +0200
Source: openslide
Architecture: source
Version: 3.4.1+dfsg-6+deb12u1
Distribution: bookworm
Urgency: medium
Maintainer: Debian Med Packaging Team <debian-med-packaging@lists.alioth.debian.org>
Changed-By: Étienne Mollier <emollier@debian.org>
Closes: 1140003
Changes:
openslide (3.4.1+dfsg-6+deb12u1) bookworm; urgency=medium
.
* Team upload.
* CVE-2026-48977.patch: new: fix CVE-2026-48977.
The change lacks attempt to apply the test case, because the binary
representation of a newly introduced test file is not possible in the
patch. (Closes: #1140003)
Checksums-Sha1:
bb20f4b32617d05055ffb783e819fddf02d6e897 2715 openslide_3.4.1+dfsg-6+deb12u1.dsc
184f0d838630e35bae1d7ca9ae47a41c62a7c0d9 20268 openslide_3.4.1+dfsg-6+deb12u1.debian.tar.xz
Checksums-Sha256:
7894705709a2f881c57ed4a7b3a61597c06856be66d18b348e897801b14baba0 2715 openslide_3.4.1+dfsg-6+deb12u1.dsc
65932795fcae6d8e5eda6bba1d06fc8b84fc7efc7e8633fe26752e891d38e015 20268 openslide_3.4.1+dfsg-6+deb12u1.debian.tar.xz
Files:
800891979a0ebfa355a929deaff72660 2715 libs optional openslide_3.4.1+dfsg-6+deb12u1.dsc
2b68b63f2fa3b334f8f01234cfb28da1 20268 libs optional openslide_3.4.1+dfsg-6+deb12u1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEEj5GyJ8fW8rGUjII2eTz2fo8NEdoFAmpDYBcUHGVtb2xsaWVy
QGRlYmlhbi5vcmcACgkQeTz2fo8NEdrECA//fMOonCmrKCdi72sVR/LEhwQyXy4t
4jL8i5YtXZaSZybzm1+jwSlSNmetW2k63giuLd3cZMdMMZirAYe792oAIYZV0HqK
ZRcktxc28PbBPf2FePIT9owSA8yB/uoh3fpvmVwtdbn2ff9OwNjC03D/pCaCXMhZ
0RMcz39r+XBxW7kssg32XG4XuRniuDmkH0fxF7IV648gTl9tQDUNGPV+0F6Rq9vF
KtHTubvcticWZJVQQhshGKy554bQxDpqmlIa4MrLx6TQvTBzkn5MKKhFU7VTgMM1
rXQAOcdnoHO0zLL+50iPeOpcPe0KcmmlmdJXKFjJNPsD8k/gDlrei30AC7Nep7XD
2B2zCENyUNle2PYoVmufbutqCtPzkgyX/TW2nuSHMqK8Ulp3XNxxwG5DzSpK+KUi
9kph8yCZvTbKgqCpdfI1AcZUxR6LnAhGvdPNcqhurlaHQj5XNF2eL8De7YAfy0Qy
Gx6hfL1pBkF/CQ0O1LDlyEUVIvfYrkRLW3mxiYkXBC7SqjTZSceuUd3cJc42GWmS
pAu1dq2coDN3pa3XSQFCEF1T9RNdgC4erhsQ8/kqStfFhx4EIXSVxUNkbEpSlUyM
pN3o3oxh1L8bUGpR4YzQ9ErZZyQW5syYL3huR7R69ttbVK8LThA35L/NEi8ykvJf
mEdG/xiksGIsBHk=
=kmRF
-----END PGP SIGNATURE-----