#1141607 trixie-pu: package patool/4.0.0-1+deb13u1

#1141607#5
Date:
2026-07-07 06:40:24 UTC
From:
To:
Dear stable release managers, please consider patool/4.0.0-1+deb13u1
for trixie.

[ Reason ]
CVE-2026-29509 reported against patool.


[ Impact ]
CVE-2026-29509 is a path traversal vulnerability. Exposing users to
such vulnerability is not trivial.

[ Tests ]
Package contain extensive testsuite which ran successfully.

[ Risks ]
The security fix patch backported from the upstream version 4.0.5 and
merged with minimal fuzz.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

#1141607#12
Date:
2026-07-14 19:29:30 UTC
From:
To:
Hi,

Please go ahead.

Thanks,

#1141607#19
Date:
2026-07-16 11:05:09 UTC
From:
To:
package release.debian.org
tags 1141607 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: patool
Version: 4.0.0-1+deb13u1

Explanation: fix path traversal vulnerability [CVE-2026-29509]

#1141607#24
Date:
2026-07-16 11:05:09 UTC
From:
To:
package release.debian.org
tags 1141607 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: patool
Version: 4.0.0-1+deb13u1

Explanation: fix path traversal vulnerability [CVE-2026-29509]