- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Hefee
- Date:
- 2026-07-13 08:19:03 UTC
- Severity:
- normal
- Tags:
[ Reason ] Fixes two upstream advisories: https://bugs.debian.org/1139716 -> https://security-tracker.debian.org/tracker/TEMP-1139716-6892B6 -> https://github.com/onionshare/onionshare/security/advisories/GHSA-v833-3823-cmhp https://bugs.debian.org/1139717 -> https://security-tracker.debian.org/tracker/TEMP-1139717-36B614 -> https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf Both issues are fixed with 2.6.4-1 in Forky already. Unfortunately 2.6.4 updated unrelated things too. So I backported the relevant patches to fix the two issues including the additional unit tests to 2.6.3 for Trixie. The securtiy team already marked those two issues as no-dsa, so the way to fix it is via p-u: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139716#20 [ Impact ] The user will still be affected by this issues: - Allows unintended disclosure of local files. - Allow a remote sender to create directories on your device. [ Tests ] Build the package and let the autopkgtests run, that has the additional tests added. [ Risks ] The patches come from upstream and could applied without changes on 2.6.3. The affected files are not changed by other commits in the diff 2.6.3..2.6.4. So a hidden side-effect is unlikely. The patches itself are small and focused. The existing tests already tests a big portion of the usages and the additional tests care about the two issues. IMO the risk to introduce new bugs is small. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in stable [x] the issue is verified as fixed in unstable [ Changes ] * Backport six upstream commits * Updated debian branch in debian/gbp.conf
Hi, Both upstream advisories (GHSA-*] now have CVE identifiers; please upload again with those included in the changelog and get the security tracker updated to match. Then we are all tying together one set of common identifiers. Thanks,
Updated - use correct CVE identifiers, as they are now available - havn't noticed before.
package release.debian.org tags 1141858 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: onionshare Version: 2.6.3-1+deb13u2 Explanation: Prevent writing files in Receive mode when file uploads are disabled [CVE-2026-54707]; Prevent empty folder from being created when no file is uploaded [CVE-2026-54706]
package release.debian.org tags 1141858 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: onionshare Version: 2.6.3-1+deb13u2 Explanation: Prevent writing files in Receive mode when file uploads are disabled [CVE-2026-54707]; Prevent empty folder from being created when no file is uploaded [CVE-2026-54706]