#1140359 nginx: CVE-2026-42055

Package:
src:nginx
Source:
src:nginx
Submitter:
Salvatore Bonaccorso
Date:
2026-07-18 16:15:02 UTC
Severity:
normal
Tags:
#1140359#5
Date:
2026-06-19 03:40:49 UTC
From:
To:
Hi,

The following vulnerability was published for nginx.

CVE-2026-42055[0]:
| NGINX Plus and NGINX Open Source have a vulnerability in the
| ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This
| vulnerability exists when the proxy_http_version to 2 or
| grpc_pass directives are used to proxy HTTP/2 traffic, the
| ignore_invalid_headers directive is set to off, and the
| large_client_header_buffers directive size is larger than 2
| megabytes. A remote, unauthenticated attacker, along with conditions
| beyond their control, could send large headers while creating an
| upstream request. This may cause a heap-based buffer overflow in the
| NGINX worker process leading to a restart. Additionally, attackers
| can execute code on systems with Address Space Layout Randomization
| (ASLR) disabled or when the attacker can bypass ASLR.    Note:
| Software versions which have reached End of Technical Support (EoTS)
| are not evaluated.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-42055
https://www.cve.org/CVERecord?id=CVE-2026-42055
[1] https://my.f5.com/manage/s/article/K000161584
[2] https://github.com/nginx/nginx/commit/131be8514da8985b15b74150521afedbf9cc4ea3

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1140359#10
Date:
2026-06-19 20:56:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140359@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jan Mojžíš <janmojzis@debian.org> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 19 Jun 2026 19:21:49 +0000
Source: nginx
Architecture: source
Version: 1.30.1-5
Distribution: unstable
Urgency: medium
Maintainer: Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-lists.debian.net>
Changed-By: Jan Mojžíš <janmojzis@debian.org>
Closes: 1140359
Changes:
 nginx (1.30.1-5) unstable; urgency=medium
 .
   * d/t/ssi-module-test: remove the test associated with the bug report,
     since the underlying bug has been fixed in bookworm
   * d/t/RFC9112: create a wrapper for RFC9112 tests, then merge d/t/proxy,
     d/t/uwsgi-RFC9112, and d/t/fastcgi-RFC9112 into the wrapper to improve
     test performance.
   * d/control: bump Standards-Version: 4.7.4, no changes
   * d/p/CVE-2026-42055.patch add, backport fix for buffer overflow
     vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module
     (CVE-2026-42055) (Closes: 1140359)
   * d/p/CVE-2026-48142.patch add, backport fix for buffer overread
     vulnerability in the ngx_http_charset_module (CVE-2026-48142)
Checksums-Sha1:
 a1ca257b8c7f81a2cb40ee21f0d2a47832b7698d 3803 nginx_1.30.1-5.dsc
 2a7faa86248f3422ee9a33652cd748fd5d7f95af 78112 nginx_1.30.1-5.debian.tar.xz
 98090886fb54d6f99b73f056b54360e96ea8b451 3113948 nginx_1.30.1-5.git.tar.xz
 a6dbf86ead95db759a88a35a7baac7321bc8514e 17484 nginx_1.30.1-5_source.buildinfo
Checksums-Sha256:
 b875ef3cd5261afa2a8b157a3fdc4be81e592252cc4f64c05872c34bf1598d5c 3803 nginx_1.30.1-5.dsc
 a0e2bda21c59182446ee4cfa38b346f858a5fdc04959cb370388ad68f4560000 78112 nginx_1.30.1-5.debian.tar.xz
 39171568c401490ea513e9d49061f0a171445a3538a9ee00f8ab3e53cf54686a 3113948 nginx_1.30.1-5.git.tar.xz
 2f19a60a94861de21baca90775e7f238ddfcf21cbd8337783bd8b58c9400eb73 17484 nginx_1.30.1-5_source.buildinfo
Files:
 0bedfe152e0dae009c674f7d6184eabe 3803 httpd optional nginx_1.30.1-5.dsc
 ef2711ca9e9f6faf0289cc46aff983bb 78112 httpd optional nginx_1.30.1-5.debian.tar.xz
 78ca4e88e9aca39ffb241ad52a862991 3113948 httpd None nginx_1.30.1-5.git.tar.xz
 d6a85730bee17d1ef0bb04c4bf967bef 17484 httpd optional nginx_1.30.1-5_source.buildinfo
Git-Tag-Info: tag=df47fe26cfc38564dbbead6b0634da24cba7303c fp=d008b0c23d8479e46b9fcb9045da517496939ff9
Git-Tag-Tagger: Jan Mojžíš <jan.mojzis@gmail.com>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmo1odkACgkQYG0ITkaD
wHkjWRAAsdAGqR76raUBLMD/Sg+ZJuHOFLwb89JgQ5chM4y9onXYp1fTt0GSoDYc
BTZUgC162mU1tXzjAVZA6scxXbr6eW4TLDZiCRpmTyiu8zKjqSkrlKGE8UKmnbmH
+q80tNzjuw5U7F/I6/BPH7jo6dfuktxGxWpAIYo01rTobtzI2z+1PY3MxFjU0cfZ
4mTLElyNLJ8YwJCIHtOtNNyGkg7Df6K7ngJMW6pBZQMK4gN429TcrIep3Ym1mf5A
RkrSnkXTuOCF6bNUUzqaLap7TAsUD1gv1XfqO33dcdVqFCmoeFPVaV6XR8N22AKe
gFkmPDtqFDGcLs/CvmmbRwRfXSShTvxFs6PtAwYtBVgTFJUp2HFo7gGR63rF9Yk/
21L5actI7VPfysBmt5OJCxKo0U4/nf3PLsOTUgN7AuEuFxjIdUVAm7DcILDHZyWk
Kzfw/ob5FD3Xrg6QfPyTM+WILmnyDfE6JZNnwYTLIY8iBl52Tkj1yRUqU1h9vGuo
ZMot+PmxBrG2P7KKCJhabZS+9grnUOAAdztn9TI3LdC6s9cquFlZpmi90GqIIAK3
NUhwaRj9WbHFBuWxG589SnMnZPtZGnsoSpLeGtY9ZAOM6G/QbF2FcPV2T9F1DV8E
WvLd37Bu13pFWQ2IlrlahfAYrjR+SZPql6dZE9EXvXChB9nBIkc=
=vfwt
-----END PGP SIGNATURE-----

#1140359#13
Date:
2026-07-01 10:52:42 UTC
From:
To:
Hello,

Bug #1140359 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/4f879c14d41ac59fe345c95fb394e88f17d5cf16

Closes: #1140359
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1140359

#1140359#18
Date:
2026-07-04 10:02:51 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140359@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Salvatore Bonaccorso <carnil@debian.org> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 27 Jun 2026 22:33:06 +0200
Source: nginx
Architecture: source
Version: 1.26.3-3+deb13u7
Distribution: trixie-security
Urgency: high
Maintainer: Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-lists.debian.net>
Changed-By: Salvatore Bonaccorso <carnil@debian.org>
Closes: 1140359 1140361
Changes:
 nginx (1.26.3-3+deb13u7) trixie-security; urgency=high
 .
   * Non-maintainer upload by the Security Team.
   * Upstream: limit header length for HTTP/2 and gRPC (CVE-2026-42055)
     (Closes: #1140359)
   * Charset: fixed another rare buffer overread in recode_from_utf8()
     (CVE-2026-48142) (Closes: #1140361)
Checksums-Sha1:
 88d2932f85883790729500395b595ee754c342b3 3953 nginx_1.26.3-3+deb13u7.dsc
 3d91dada31ac9fee539f1ddfbef14084319df5cb 92748 nginx_1.26.3-3+deb13u7.debian.tar.xz
 f449aab4057bbf1e25e24370f37c0dcc26febf77 6308 nginx_1.26.3-3+deb13u7_source.buildinfo
Checksums-Sha256:
 12ea342366d81030e59e3a0ac9591ca549f5da023d85055f0a25d99e68378381 3953 nginx_1.26.3-3+deb13u7.dsc
 19fcf637728c01356f4c80909812b32bc38d6f10eabc1e7fa2bb2c6fbcf27474 92748 nginx_1.26.3-3+deb13u7.debian.tar.xz
 e99e0c54070ead7a45891e72c02da52622aa924b546c8f51d3da640a5b390dc1 6308 nginx_1.26.3-3+deb13u7_source.buildinfo
Files:
 6df53f7005030c662573cc9fd5b3b178 3953 httpd optional nginx_1.26.3-3+deb13u7.dsc
 17694b7c9829210f1401ed3471e95d5e 92748 httpd optional nginx_1.26.3-3+deb13u7.debian.tar.xz
 4c57def4cc45df1daa22ac88f04926ec 6308 httpd optional nginx_1.26.3-3+deb13u7_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQKmBAEBCgCQFiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmpBhzxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQSHGNhcm5pbEBk
ZWJpYW4ub3JnAAoJEAVMuPMTQ89EbgsP/2Posd1cuhRcPHG6J0ElVbi3VsCY1muG
woOR6qR5Ru3DrVujRiGVu0GRAO2k0fwCIRzdVBOaxDzZoi75/1jHLJ3CByd19JKq
2mZ+qzrcIfpX2UyuBUfIu+ziRJXIaxMyNNaWXA4AB+owA/6VZjILGcyhHMFD0Jy5
SkAZ09A6Nginxkzixp5Lx+NWSALZvOaQ0UFl7x262E4z3dpCMWSOUu+uiOL45U+Q
OOVAf4z7mblLKLM7kaTOAPJBnw3zM4ewhKVtcttct/NHC52NhCz/VrXu1f0gs1PF
hWyQV/oj9Gs85t2s9Cf7xA8qvGdsWjwgz5xYqBY5yy5GEEio9klzFWZFtrUh/xWW
NsS9+K0SxVwaLRO8a5slNrlDuFQB1UPk8B/um1HHRozoPzVYdNA1ByKW+ldvsve9
KOiE9zXgOq29I9Vdw7e3CQv1SfZquAhRv87CwARaIEz4YBYWFbyjFtnKUVseVKzf
OOhS2DOzVSSi70id8+Q0MXJQyesk57WZ7c+feJvpWF2B9Wnn3pMEkh8XsOqz1ZUb
9qduarfjZPhpHS7s4OcC+XzMU0ESAqcLG99WSNyxVfaBw+fdI5FvGham3WEzR6hE
B++Bdt6+P/tF5+fP2C7vkrkLwgLns+Zn5rG8B2CTDbgcCoIjUrxcUqAsREPLRIkm
p9yMtGeN3vgt
=BSjN
-----END PGP SIGNATURE-----

#1140359#23
Date:
2026-07-04 10:32:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
nginx, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140359@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Carlos Henrique Lima Melara <charlesmelara@riseup.net> (supplier of updated nginx package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 30 Jun 2026 22:05:01 -0300
Source: nginx
Architecture: source
Version: 1.22.1-9+deb12u9
Distribution: bookworm-security
Urgency: medium
Maintainer: Debian Nginx Maintainers <pkg-nginx-maintainers@alioth-lists.debian.net>
Changed-By: Carlos Henrique Lima Melara <charlesmelara@riseup.net>
Closes: 1140359 1140361
Changes:
 nginx (1.22.1-9+deb12u9) bookworm-security; urgency=medium
 .
   * Non-maintainer upload by the LTS Team.
   * debian/gbp.conf: set debian-branch to debian/bookworm.
   * debian/patches: import upstream patches to fix vulnerabilities.
       - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359)
       - CVE-2026-48142.patch: cherry-pick from upstream. (Closes: #1140361)
   * debian/tests/abicheck: cherry-pick from debain/trixie, remove chown, add
     warn when it fails and remove needs-root restriction.
Checksums-Sha1:
 d3f4e6721c4f3a852fa0a604bc75900dfe87d408 3594 nginx_1.22.1-9+deb12u9.dsc
 45a89797f7c789287c7f663811efbbd19e84f154 1073948 nginx_1.22.1.orig.tar.gz
 7f9c8b261edecb645f4c0a835f7422f2486cee42 86524 nginx_1.22.1-9+deb12u9.debian.tar.xz
 e82648b4b875593d65570b2d01d50baed342e986 6049 nginx_1.22.1-9+deb12u9_source.buildinfo
Checksums-Sha256:
 28baa4abda06503ae8ecde6e9f049905de7c172d6ec767636628bfcd87499cf4 3594 nginx_1.22.1-9+deb12u9.dsc
 9ebb333a9e82b952acd3e2b4aeb1d4ff6406f72491bab6cd9fe69f0dea737f31 1073948 nginx_1.22.1.orig.tar.gz
 3aebca44037e31b4148cec5a10dc673fdac176411aaa65a0094135895d154223 86524 nginx_1.22.1-9+deb12u9.debian.tar.xz
 7552e7d6aa39cdd6d5d4dfec8533d3670a50330ec1b6a18f23b26e7ee41915cf 6049 nginx_1.22.1-9+deb12u9_source.buildinfo
Files:
 ef6570185853d8af66df580ff40760d5 3594 httpd optional nginx_1.22.1-9+deb12u9.dsc
 8296d957561aeed0261d9be4d3decaec 1073948 httpd optional nginx_1.22.1.orig.tar.gz
 4b5846cc93e3081f11259b9dfa3aa12e 86524 httpd optional nginx_1.22.1-9+deb12u9.debian.tar.xz
 7f5d9ff00943baf3ad0e17930d7ec008 6049 httpd optional nginx_1.22.1-9+deb12u9_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJNBAEBCgA3FiEECgzx8d8+AINglLHJt4M9ggJ8mQsFAmpH5z4ZHGNoYXJsZXNt
ZWxhcmFAcmlzZXVwLm5ldAAKCRC3gz2CAnyZC61iD/kB74h3E0bZ35vjjuLI5LmI
/FYTJlAJoRaUBvHi7tPKWLIm82/pGX6nB4wJ6/vUgiByCtYIHCLsch1cjLl05nt2
F0Ye2RCGng5DqoFTkGcWhKFHvrstZ4it+Rxb8vAOPYtxw4luLhUqW6VEMuzdicS0
+7lVDCRbE+wF6P5xAup7NO6wNlkJkTwOaTZHmF/wPzmuYj8oTsBACr2be1RdMMVo
PIGqXuj31qMLviEn0dnmnlgYng7W9UHEI6KaJfHepr+UAjpIwEhg7qxAT7lqqJCo
hOMrEudmoLUcUHj8/HtMZHYHWoP5HNVQj4RqmXf6a/X8hIjRcv44qYh1cqEaSysJ
6+gDJW19l8W45t8RJGv+7d93dp/wFvPpw+rEQsTx+YORntTMrmTj5VXBiyZe84wq
HxiTUyWi+ZP1t549MENZfuvAvwmvDGshkFu5e6QM7KGFiifXZf7SKRr0+GBdMWTO
PaFAUmOIdVd/mhrFEXzA8xL/HLaiOwwRRTbKJHiklnq03K+z+2kj2FtAYr+1fg8N
SCBc5L6STPLh9D1Ro9ByW7Eq+3r+Hlh2PLxZ8D+uS1+YVBnkvdFb1Z+lbv85fjsV
W0oPEmBft70zJDm5UkSkOcRclNX3nDx+VUUSMjow97mQfsCk44Z/mjqErHxdoEek
UeFMtuJq+99V8Y+bPu6pVQ==
=dPEl
-----END PGP SIGNATURE-----

#1140359#24
Date:
2026-07-07 18:19:37 UTC
From:
To:
Hello,

Bug #1140359 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/37297a5094f0d6c560fb5a259f4d7bda543518dd
------------------------------------------------------------------------ Import Debian changes 1.18.0-6.1+deb11u8 nginx (1.18.0-6.1+deb11u8) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bullseye. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream; (Closes: #1140361) - FIX-HTTP2bomb.patch: backport from upstream. (Closes: #1138794) . nginx (1.18.0-6.1+deb11u7) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/patches/CVE-2026-9256.patch: cherry-pick from upstream. (Closes: #1137339) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140359
#1140359#25
Date:
2026-07-07 19:02:35 UTC
From:
To:
Hello,

Bug #1140359 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/37297a5094f0d6c560fb5a259f4d7bda543518dd
------------------------------------------------------------------------ Import Debian changes 1.18.0-6.1+deb11u8 nginx (1.18.0-6.1+deb11u8) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bullseye. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream; (Closes: #1140361) - FIX-HTTP2bomb.patch: backport from upstream. (Closes: #1138794) . nginx (1.18.0-6.1+deb11u7) bullseye-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/patches/CVE-2026-9256.patch: cherry-pick from upstream. (Closes: #1137339) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140359
#1140359#26
Date:
2026-07-08 01:35:49 UTC
From:
To:
Hello,

Bug #1140359 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/2004a82149c5344b8b29d8a3c551c0a411ca8c27
------------------------------------------------------------------------ Import Debian changes 1.26.3-3+deb13u7 nginx (1.26.3-3+deb13u7) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Upstream: limit header length for HTTP/2 and gRPC (CVE-2026-42055) (Closes: #1140359) * Charset: fixed another rare buffer overread in recode_from_utf8() (CVE-2026-48142) (Closes: #1140361) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140359
#1140359#27
Date:
2026-07-08 01:39:24 UTC
From:
To:
Hello,

Bug #1140359 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/2004a82149c5344b8b29d8a3c551c0a411ca8c27
------------------------------------------------------------------------ Import Debian changes 1.26.3-3+deb13u7 nginx (1.26.3-3+deb13u7) trixie-security; urgency=high . * Non-maintainer upload by the Security Team. * Upstream: limit header length for HTTP/2 and gRPC (CVE-2026-42055) (Closes: #1140359) * Charset: fixed another rare buffer overread in recode_from_utf8() (CVE-2026-48142) (Closes: #1140361) ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140359
#1140359#28
Date:
2026-07-18 16:12:39 UTC
From:
To:
Hello,

Bug #1140359 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/c2d45bd8fe45473bd592403961e566c30fff5c30
------------------------------------------------------------------------ Import Debian changes 1.22.1-9+deb12u9 nginx (1.22.1-9+deb12u9) bookworm-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bookworm. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream. (Closes: #1140361) * debian/tests/abicheck: cherry-pick from debain/trixie, remove chown, add warn when it fails and remove needs-root restriction. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140359
#1140359#29
Date:
2026-07-18 16:13:34 UTC
From:
To:
Hello,

Bug #1140359 in nginx reported by you has been fixed in the Git repository.
You can see the commit message below and you can check the diff of the fix at:

https://salsa.debian.org/nginx-team/nginx/-/commit/c2d45bd8fe45473bd592403961e566c30fff5c30
------------------------------------------------------------------------ Import Debian changes 1.22.1-9+deb12u9 nginx (1.22.1-9+deb12u9) bookworm-security; urgency=medium . * Non-maintainer upload by the LTS Team. * debian/gbp.conf: set debian-branch to debian/bookworm. * debian/patches: import upstream patches to fix vulnerabilities. - CVE-2026-42055.patch: backport from upstream; (Closes: #1140359) - CVE-2026-48142.patch: cherry-pick from upstream. (Closes: #1140361) * debian/tests/abicheck: cherry-pick from debain/trixie, remove chown, add warn when it fails and remove needs-root restriction. ------------------------------------------------------------------------ (this message was generated automatically) -- Greetings https://bugs.debian.org/1140359