- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Matheus Polkorny
- Date:
- 2026-07-13 08:19:03 UTC
- Severity:
- normal
- Tags:
[ Reason ] Fix CVE-2026-33936 by backporting the upstream fix. Additionally, import an upstream test fix required for the package test suite to pass with Python 3.13. [ Impact ] Malformed DER-encoded private keys can trigger unexpected exceptions, leading to a denial of service. [ Tests ] The package was built successfully and the test suite passes with the included fixes. [ Risks ] Low. The update consists of upstream patches: - the security fix for CVE-2026-33936; - a test-only adjustment to keep the test suite compatible with newer Python versions. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] - CVE-2026-33936: Import upstream patch. - Fix-tests-with-new-Python: Import upstream patch to fix test failures with Python 3.13. [ Other info ] The upload will be sponsored by @josue.
FTR, this test was broken by the CVE-2026-3446 fix in 3.13.5-2+deb13u2 that was included in the 13.5 point release. cu Adrian
Control: tags -1 + confirmed Please go ahead. Regards, Adam
Hi Matheus, Too late for the upcoming point release, but can you still upload so that it can be included in the next one? Regards, Salvatore
Hello Salvatore, I don't have permission to upload this package. @josue has approved the MR(bookworm) [1], but it still needs a sponsor. If everything looks good to you, please go ahead and upload it. [1] https://salsa.debian.org/python-team/packages/python-ecdsa/-/merge_requests/1 Thanks!
Hi Matheus, Ok right, should have realized that this might have the problem. In this case can you route this through your sponsors? Regards, Salvatore
package release.debian.org tags 1140299 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: python-ecdsa Version: 0.19.1-1+deb13u1 Explanation: prevent exceptions when handling truncated DER [CVE-2026-33936]
package release.debian.org tags 1140299 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: python-ecdsa Version: 0.19.1-1+deb13u1 Explanation: prevent exceptions when handling truncated DER [CVE-2026-33936]