#1141490 openconnect: Updated PaloAlto PAN-OS 11.1.13+ requires a change due to CVE-2026-0257 mitigation #1141490
- Package:
- openconnect
- Source:
- openconnect
- Description:
- open client for various network vendors SSL VPNs
- Submitter:
- Adam Cecile
- Date:
- 2026-07-30 08:35:02 UTC
- Severity:
- normal
- Tags:
Hello, Updated Palo Alto servers require a patch to work correctly. Currently cookies being resent are not trusted anymore, leading to multiple authentication steps to get in. Upstream fixed the issue with https://gitlab.com/openconnect/openconnect/-/commit/77e061a2f15f32cdbacbc308f66f84a508569744 and I'm going to update Trixie package with this patch for my own (and team) personal use. Would you be interested in a debdiff ? Or maybe a PR if the package is hosted on Salsa ? Imho, this fix should be backported to Debian stable. Best regards, Adam.
Hello, Please find attached a diff on the packaging including upstream patch. For the record, upstream patch is currently living in a non-merged branch and several hunks had to be applied manually against 9.12. Adam.
Hello Adam, I tried to apply your patch after updating to the latest upstream release, but the patch is not merged, and doesn't apply anymore. You say it comes from upstream, but Debian upstream repo is tracked at git://git.infradead.org/users/dwmw2/openconnect.git So please update the patch for the newer version and make sure upstream applies it, in order to drop on the next release thanks Gianfranco
Hello Adam, I see the patch, but unfortunately after updating to 9.21 I found that it is not applying anymore. So, please provide an updated patch and make sure it gets merged into mainline, so on next upstream release we can drop it. thanks Gianfranco
Hello, Sadly this is still not merged upstream, not sure why... Maybe you could try the upstream branch directly ? In my debdiff I had to fix a few hunks manually because an upstream keepalive feature was missing from Debian's 13 version. See here: https://gitlab.com/openconnect/openconnect/-/compare/master...847-globalprotect-cookie-changes If you need me for a Palo Alto test, don't hesitate to ping me. Regards, Adam.
Hello, Bug #1141490 in openconnect reported by you has been fixed in the Git repository and is awaiting an upload. You can see the commit message below and you can check the diff of the fix at: https://salsa.debian.org/debian/openconnect/-/commit/b0e84fda50898f8e33cae3fd91a097939d17edf9 (this message was generated automatically) -- Greetings https://bugs.debian.org/1141490
We believe that the bug you reported is fixed in the latest version of openconnect, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 1141490@bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Gianfranco Costamagna <locutusofborg@debian.org> (supplier of updated openconnect package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster@ftp-master.debian.org) Format: 1.8 Date: Thu, 30 Jul 2026 10:15:32 +0200 Source: openconnect Built-For-Profiles: noudeb Architecture: source Version: 9.21-4 Distribution: unstable Urgency: medium Maintainer: Mike Miller <mtmiller@debian.org> Changed-By: Gianfranco Costamagna <locutusofborg@debian.org> Closes: 1141490 Changes: openconnect (9.21-4) unstable; urgency=medium . * Team upload * Update dependencies for ports * Add patch to sync master latest fixes * Add upstream proposed patch to fix PaloAlto (Closes: #1141490) * Fix old fsf address lintian warning * Update std-version to 4.7.4, no changes required Checksums-Sha1: fdd8327fcc91d8ff7d4a9f2668af2786f8d779b3 2811 openconnect_9.21-4.dsc 270a2d8fae3bf217d9a5e4c37f4d857b2e918b7e 43192 openconnect_9.21-4.debian.tar.xz 1478f7073a181e4498814dcbe4e68138c8c188ba 13579 openconnect_9.21-4_source.buildinfo Checksums-Sha256: 48f3487ea6a2ab007cec6126db51a284cf6ca7a5b04cb5f639f9358b5e9bddcc 2811 openconnect_9.21-4.dsc ad970fe594238e92569d5fb00ef4ae0a0e53fe44cf3e47f9b4b21245ac3784c0 43192 openconnect_9.21-4.debian.tar.xz 58947fd0cdf6c3afa651da17eb206af280649154ea3095340d20f1d82f560eb0 13579 openconnect_9.21-4_source.buildinfo Files: 86f12cfaa1c4749e296471122320c833 2811 net optional openconnect_9.21-4.dsc 62fdf4dfd0667d36b400198420773189 43192 net optional openconnect_9.21-4.debian.tar.xz f9f21836365127259a9ace1b56077e10 13579 net optional openconnect_9.21-4_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJNBAEBCgA3FiEEkpeKbhleSSGCX3/w808JdE6fXdkFAmprCHwZHGxvY3V0dXNv ZmJvcmdAZGViaWFuLm9yZwAKCRDzTwl0Tp9d2W1bD/4iocA+P4C/YK3wPdwLrJ9c KrTfAnN+70kAZxbaviqzg3g9X5WBuwcWU91/jc0yKg2lwk9R+MPo0Pl2hcc0Yii7 3eCndf/avZdJXyv6dNT0mciUHoeSjReXQSMF5Q4SVx6d7V0R3pKHkr9vJT951yDC 04h80wSUqRQHaBb25JVbsy3lg8+7neIVsU/mkvCQOIgZp/F4feI1/kZnk61GqdZU xci3xNIMeucbSZtUm3oLHx+X+hFP6Y+byAi0XK/fpFde5KSypoD8xnBRh1olvZod ++TUncy/TqMGJUiHaPeEyBhMXH3Rjrqgm6NQ28zWP7prHVfnoQm4jIt9Dc930Sw+ rWnlsNuOy7TqajV/A08wIZOWhl765fJAlqGjVEakp+CYvx7wJA1zpJFTKzytB1rm tvwkd3c8e+yMYhrAFkb2YzveCHS/yzlHKURUNbxuWWBD3bH8uMX3mBgfZ7pz7hPp JrFeVpqFlTIksJZTqa0GN8scAz0z7A0ilh34zFonwCZ0UVrxS3pRvf6gx5AH8rW6 GR1jV3GG3E1KuDw+03Z5GxiMs+ohuReSpUxgLrBF7vtb2f5uZMKQm+/hx2OLYugD GEvwtYRLGZ1u+AhxuC1mnOIi8B4Dlxd4OOo8lCoCTXEK4iHms8oLaU0oj/DEsqI4 kRIYA3puV6yslRay/z9UEg== =McUK -----END PGP SIGNATURE-----