- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Abhijith PA
- Date:
- 2026-07-16 11:07:03 UTC
- Severity:
- normal
- Tags:
Dear stable release managers, please consider patool/4.0.0-1+deb13u1 for trixie. [ Reason ] CVE-2026-29509 reported against patool. [ Impact ] CVE-2026-29509 is a path traversal vulnerability. Exposing users to such vulnerability is not trivial. [ Tests ] Package contain extensive testsuite which ran successfully. [ Risks ] The security fix patch backported from the upstream version 4.0.5 and merged with minimal fuzz. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable
Hi, Please go ahead. Thanks,
package release.debian.org tags 1141607 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: patool Version: 4.0.0-1+deb13u1 Explanation: fix path traversal vulnerability [CVE-2026-29509]
package release.debian.org tags 1141607 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: patool Version: 4.0.0-1+deb13u1 Explanation: fix path traversal vulnerability [CVE-2026-29509]