#1140299 trixie-pu: package python-ecdsa/0.19.1-1+deb13u1

#1140299#5
Date:
2026-06-17 20:27:30 UTC
From:
To:
[ Reason ]
Fix CVE-2026-33936 by backporting the upstream fix.
Additionally, import an upstream test fix required for the
package test suite to pass with Python 3.13.

[ Impact ]
Malformed DER-encoded private keys can trigger unexpected exceptions,
leading to a denial of service.

[ Tests ]
The package was built successfully and the test suite passes
with the included fixes.

[ Risks ]
Low. The update consists of upstream patches:
- the security fix for CVE-2026-33936;
- a test-only adjustment to keep the test suite compatible with newer
  Python versions.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
- CVE-2026-33936: Import upstream patch.
- Fix-tests-with-new-Python: Import upstream patch
  to fix test failures with Python 3.13.

[ Other info ]
The upload will be sponsored by @josue.

#1140299#12
Date:
2026-06-18 08:36:01 UTC
From:
To:
FTR, this test was broken by the CVE-2026-3446 fix in 3.13.5-2+deb13u2
that was included in the 13.5 point release.

cu
Adrian

#1140299#17
Date:
2026-06-30 05:47:23 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1140299#24
Date:
2026-07-07 17:15:03 UTC
From:
To:
Hi Matheus,

Too late for the upcoming point release, but can you still upload so
that it can be included in the next one?

Regards,
Salvatore

#1140299#29
Date:
2026-07-07 22:41:35 UTC
From:
To:
Hello Salvatore,

I don't have permission to upload this package. @josue has approved the
MR(bookworm) [1], but it still needs a sponsor. If everything looks good
to you, please go ahead and upload it.
[1] https://salsa.debian.org/python-team/packages/python-ecdsa/-/merge_requests/1

Thanks!

#1140299#34
Date:
2026-07-09 05:56:56 UTC
From:
To:
Hi Matheus,

Ok right, should have realized that this might have the problem. In
this case can you route this through your sponsors?

Regards,
Salvatore

#1140299#41
Date:
2026-07-13 08:18:33 UTC
From:
To:
package release.debian.org
tags 1140299 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: python-ecdsa
Version: 0.19.1-1+deb13u1

Explanation: prevent exceptions when handling truncated DER [CVE-2026-33936]

#1140299#44
Date:
2026-07-13 08:18:33 UTC
From:
To:
package release.debian.org
tags 1140299 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: python-ecdsa
Version: 0.19.1-1+deb13u1

Explanation: prevent exceptions when handling truncated DER [CVE-2026-33936]