#1140922 logback: CVE-2025-11226 CVE-2026-13006

Package:
src:logback
Source:
src:logback
Submitter:
Salvatore Bonaccorso
Date:
2026-09-13 03:35:04 UTC
Severity:
normal
Tags:
#1140922#5
Date:
2026-06-28 12:18:06 UTC
From:
To:
Hi,

The following vulnerabilities were published for logback.

CVE-2025-11226[0]:
| ACE vulnerability in conditional configuration file processing  by
| QOS.CH logback-core up to and including version 1.5.18 in Java
| applications, allows an attacker to execute arbitrary code by
| compromising an existing logback configuration file or by injecting
| an environment variable before program execution.    A successful
| attack requires the presence of Janino library and Spring Framework
| to be present on the user's class path. In addition, the attacker
| must  have write access to a  configuration file. Alternatively, the
| attacker could inject a malicious  environment variable pointing to
| a malicious configuration file. In both  cases, the attack requires
| existing privilege.


CVE-2026-13006[1]:
| ACE vulnerability in conditional configuration file processing  by
| QOS.CH logback-core up to and including version 1.5.35 in Java
| applications, allows an attacker to execute arbitrary code
| circumventing existing protections against CVE-2025-11226
| by compromising an existing logback configuration file or by
| injecting an environment variable before program execution.    A
| successful attack requires the presence of Janino library to be
| present on the user's class path. In addition, the attacker must 
| have write access to a  configuration file. Alternatively, the
| attacker could inject a malicious  environment variable pointing to
| a malicious configuration file. In both  cases, the attack requires
| existing privilege.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-11226
https://www.cve.org/CVERecord?id=CVE-2025-11226
[1] https://security-tracker.debian.org/tracker/CVE-2026-13006
https://www.cve.org/CVERecord?id=CVE-2026-13006

Regards,
Salvatore

#1140922#10
Date:
2026-09-13 03:33:46 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
logback, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1140922@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Jérôme Charaoui <jerome@riseup.net> (supplier of updated logback package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 12 Sep 2026 21:01:00 -0400
Source: logback
Architecture: source
Version: 1:1.6.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: Jérôme Charaoui <jerome@riseup.net>
Closes: 1091319 1091320 1126748 1138632 1139180 1140922 1146719
Changes:
 logback (1:1.6.3-1) unstable; urgency=medium
 .
   * Team upload.
   * New upstream version 1.6.3, fixes CVE-2026-19880, CVE-2026-13006,
     CVE-2026-10532, CVE-2026-9828, CVE-2026-1225, CVE-2025-11226,
     CVE-2026-1225, CVE-2024-12801, CVE-2024-12798 (Closes: #1146719, #1140922,
     #1139180, #1138632, #1126748, #1091320, #1091319)
     - The logback-access module is no longer part of the upstream project, and
       will instead available via the new logback-access source package, see ITP
       #1146286.
   * update poms
   * refresh maven rules
   * drop obsolete lintian overrides
   * d/control: build with headless jdk
   * d/control: update build dependencies
   * d/control: add liblogback-access-java to Suggests
   * d/copyright: drop obsolete Files-Excluded stanza
   * d/copyright: refresh upstream copyright per LICENSE.txt
   * d/copyright: upstream switch to EPL-2.0
   * d/NEWS: add entry about logback-access split
   * d/patches: drop obsolete patches
   * d/patches: new patch to use older jansi package
   * d/upstream: add metadata
   * d/watch: update to v5 format
   * Remove redundant Priority: optional from source stanza.
   * Removed Rules-Requires-Root
   * Update standards version to 4.7.4, no changes needed.
Checksums-Sha1:
 3fcdbfe728bd4b854e424cc8af739b5774b81570 1501 logback_1.6.3-1.dsc
 a33cdcd844ad78821a0fe2a9d0b7ae842e3aeb5e 581848 logback_1.6.3.orig.tar.xz
 ef7c277792396a74709751c119ee002b7dda1f63 11664 logback_1.6.3-1.debian.tar.xz
 a81c70cc5c219903aed85221e95e2db959029903 10967 logback_1.6.3-1_amd64.buildinfo
Checksums-Sha256:
 62c2dd5927e15e8531300cdd24f592192457d9d22d285ecdc27685efaa401796 1501 logback_1.6.3-1.dsc
 9c971ebb0dd62936a671677868dc1845cd4a1596f360fcf08732886941eec1db 581848 logback_1.6.3.orig.tar.xz
 7907eccc8216dcfff25dcdf97dd8943cc7f364f2b69daa4c0d9444a2c48bac22 11664 logback_1.6.3-1.debian.tar.xz
 dd182d59f783b2aba5821265ba752504fbc89ab7af14d696089f95882507a335 10967 logback_1.6.3-1_amd64.buildinfo
Files:
 f3a509ced2a453ac51e8c2f3f5e972b1 1501 java optional logback_1.6.3-1.dsc
 945ffe907d4a89388ddf02875c54ca68 581848 java optional logback_1.6.3.orig.tar.xz
 e9bef2aee264173c75036c5275081a8e 11664 java optional logback_1.6.3-1.debian.tar.xz
 ece5d76203c866ebb8c5a733785a8790 10967 java optional logback_1.6.3-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQTAq04Rv2xblqv/eu5pxS9ljpiFQgUCaqYXFgAKCRBpxS9ljpiF
QrshAP9a6EQ5kXGAwx0T8wyJ6CjpK//whEVihp69zxb/4/NIewD/Z0vcQbAXGJOY
ADZga36BTG4F2Y31wjr4II8SG2WJDAk=
=zSSw
-----END PGP SIGNATURE-----