#1141858 trixie-pu: package onionshare/2.6.3+deb13u1

#1141858#5
Date:
2026-07-11 12:28:03 UTC
From:
To:
[ Reason ]
Fixes two upstream advisories:

https://bugs.debian.org/1139716
-> https://security-tracker.debian.org/tracker/TEMP-1139716-6892B6
-> https://github.com/onionshare/onionshare/security/advisories/GHSA-v833-3823-cmhp

https://bugs.debian.org/1139717
-> https://security-tracker.debian.org/tracker/TEMP-1139717-36B614
-> https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf

Both issues are fixed with 2.6.4-1 in Forky already. Unfortunately 2.6.4
updated unrelated things too. So I backported the relevant patches to fix
the two issues including the additional unit tests to 2.6.3 for Trixie.

The securtiy team already marked those two issues as no-dsa, so the way
to fix it is via p-u:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139716#20

[ Impact ]
The user will still be affected by this issues:
- Allows unintended disclosure of local files.
- Allow a remote sender to create directories on your device.

[ Tests ]
Build the package and let the autopkgtests run, that has the additional
tests added.

[ Risks ]

The patches come from upstream and could applied without changes on
2.6.3. The affected files are not changed by other commits in the diff
2.6.3..2.6.4. So a hidden side-effect is unlikely.
The patches itself are small and focused. The existing tests already
tests a big portion of the usages and the additional tests care about
the two issues.
IMO the risk to introduce new bugs is small.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
* Backport six upstream commits
* Updated debian branch in debian/gbp.conf

#1141858#12
Date:
2026-07-11 15:54:52 UTC
From:
To:
Hi,

Both upstream advisories (GHSA-*] now have CVE identifiers; please upload
again with those included in the changelog and get the security tracker
updated to match. Then we are all tying together one set of common
identifiers.

Thanks,

#1141858#19
Date:
2026-07-11 17:33:59 UTC
From:
To:
Updated - use correct CVE identifiers, as they are now available - havn't
noticed before.

#1141858#24
Date:
2026-07-13 08:18:30 UTC
From:
To:
package release.debian.org
tags 1141858 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: onionshare
Version: 2.6.3-1+deb13u2

Explanation: Prevent writing files in Receive mode when file uploads are disabled [CVE-2026-54707]; Prevent empty folder from being created when no file is uploaded [CVE-2026-54706]

#1141858#29
Date:
2026-07-13 08:18:30 UTC
From:
To:
package release.debian.org
tags 1141858 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: onionshare
Version: 2.6.3-1+deb13u2

Explanation: Prevent writing files in Receive mode when file uploads are disabled [CVE-2026-54707]; Prevent empty folder from being created when no file is uploaded [CVE-2026-54706]