- Package:
- src:open-isns
- Source:
- src:open-isns
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-01 18:41:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for open-isns. CVE-2026-55995[0]: | A Double Free vulnerability in open-iscsi allows | an unauthenticated MITM attacker to cause DoS. This issue | affects open-iscsi: from ? through | 56718d4e9d1a4f51c30697b5c0534144bb41c9bb. (note this is is really in open-isns, not open-iscsi source as in the oficial CVE descirption, they reference to the [1] commit as fix). If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-55995 https://www.cve.org/CVERecord?id=CVE-2026-55995 [1] https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
open-isns, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143053@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Chris Hofstaedtler <zeha@debian.org> (supplier of updated open-isns package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 31 Jul 2026 19:09:07 +0200
Source: open-isns
Architecture: source
Version: 0.103-1
Distribution: unstable
Urgency: medium
Maintainer: Debian iSCSI Maintainers <open-isns@packages.debian.org>
Changed-By: Chris Hofstaedtler <zeha@debian.org>
Closes: 1143053
Changes:
open-isns (0.103-1) unstable; urgency=medium
.
* Team upload.
* New upstream version 0.103, fixes CVE-2026-55995 (Closes: #1143053)
* d/control: set X-Style black
* Switch build system to meson. Upstream replaced the buildsystem.
This also drops building static libraries.
Checksums-Sha1:
0599816c652f03fb0240a4943f6b4d5703432c32 2380 open-isns_0.103-1.dsc
7955845c0e55d6bdd1cbbd8b709dc124c3c1e7a7 255027 open-isns_0.103.orig.tar.gz
ddb0fb54208925d98cf424916f1e7cfd2a2c036c 18516 open-isns_0.103-1.debian.tar.xz
e662bdc8a09ceed493c432632debf9e993bce5cc 9184 open-isns_0.103-1_arm64.buildinfo
Checksums-Sha256:
fcc309bcb4e15f87c308cfbd1bf94089e17549f0c0d746280b4a840c71fd1590 2380 open-isns_0.103-1.dsc
4cbbb4a0b5d75466904c7f398ff705106a116a2107a30c8dfd5ea2eba5513542 255027 open-isns_0.103.orig.tar.gz
a01892185c8728da9abc2d5b74c333bb71dc408f90a55986bfb338294b40421f 18516 open-isns_0.103-1.debian.tar.xz
2ccc83d5b300e4d3a476f1f9f484367533262912e5309f3c338bdbfbda137f46 9184 open-isns_0.103-1_arm64.buildinfo
Files:
316844ca19f875b5d956071977883948 2380 net optional open-isns_0.103-1.dsc
87c5e08bedace78ad5e2ea6113f38afe 255027 net optional open-isns_0.103.orig.tar.gz
d53d81e2363eb264298155318e34a487 18516 net optional open-isns_0.103-1.debian.tar.xz
3f9b3d54cda6a74b280ff19d23e86b09 9184 net optional open-isns_0.103-1_arm64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfRrP+tnggGycTNOSXBPW25MFLgMFAmps14sACgkQXBPW25MF
LgMjXQ/+NQKP+m+hT+wDZAOzeBdbHQ6HEciY1DKPs+vowiW6WAVfzod98piKXoHg
4qnoYMex7OpzgNxayj3btbEld8LlsJX1TgZuHeCh+zEVXH5/DNIArZBPqQAvQ75j
FP8LSptl04/QF1NBdbkJXbhAx5OvvxDQTYi+cEVSUFOaOli/JTd71mZqDOU4OaLU
G7dhq5lm2Zl63HQ2UnaTwyAw7K42DNt+mnCycmKF1QBDvzrrNQvXzktVvnTLKDly
aspTzJqWUXVmW+UJjk+G+txKuG37rwdzOxI6GLS/dfpC2LJhdhnwIPY5E2e1US/y
1aGpTpHXlWZTcj7SilIdzGgH1wtp+PVpzloJFbytQ/AJdaSkSQjEu38QGXnHoNZX
QUMG9aQA1/TSaDlDezS2ps1fZwxzMFFWGIqc/XJg13+/oSrvmQLPwXREvg6GROoM
JbAX+kCfIqxP2nbYLwTmyS1zTI5QxZpE5Bl9RfIMunjm3Hl2mgfybVgG5ERociaV
z/9tIU9nQ5x1eK3T1DJM3WcG7LAB6uqH+x47kwSBYL1fFfCXyo0w9J4QupvHKBrM
zubUv9ayZ5ZBrRMzAUw9AskcyD57WDI4N/YO2TTBF11B/APTimnmqga3Ara9wk7S
AUrGW29mPx/VVUUkRz6MkF02YywqNZSflEPqqOSahpvUdm5q9S4=
=m1MK
-----END PGP SIGNATURE-----
Hi Chris, I think that is not correct? https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb is not included in v0.103 or do I miss something? p.s.: I tend to mark this no-dsa, do you agree? Regards, Salvatore
You are, of course, correct. Sorry. I'm uploading -2 with the fix cherry-picked. I think so - however it's a bit unclear to me how to reach the affected code. Best, Chris
We believe that the bug you reported is fixed in the latest version of
open-isns, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1143053@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Chris Hofstaedtler <zeha@debian.org> (supplier of updated open-isns package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 01 Aug 2026 14:32:19 +0200
Source: open-isns
Architecture: source
Version: 0.103-2
Distribution: unstable
Urgency: medium
Maintainer: Debian iSCSI Maintainers <open-isns@packages.debian.org>
Changed-By: Chris Hofstaedtler <zeha@debian.org>
Closes: 1143053
Changes:
open-isns (0.103-2) unstable; urgency=medium
.
* Team upload.
* Pick upstream fix for CVE-2026-55995 (Closes: #1143053)
* d/changelog: remove incorrect CVE fix mention in 0.103-1
* d/control: remove Testsuite: autopkgtest to fix lintian warning
unnecessary-testsuite-autopkgtest-field
* Remove Christian Seiler from Uploaders.
Thank you for your past contributions.
Checksums-Sha1:
aa9292d7ea016444bb7bb98ef37985f9647c29d8 2341 open-isns_0.103-2.dsc
42eeca3023a4fd9c78ac63a0df2fae70da11cb33 19136 open-isns_0.103-2.debian.tar.xz
47b87b4b5610b2532e095a837cc45560375555b0 9184 open-isns_0.103-2_arm64.buildinfo
Checksums-Sha256:
3bcedfc84ab333e241f8c1dd4df888db6c811ffabdc97fe038bd03d752f08f3d 2341 open-isns_0.103-2.dsc
9a30ed7a6cefa1866f33f88ce67f6ee88f2e1bc59d220dc8cecb2d2f6feaf896 19136 open-isns_0.103-2.debian.tar.xz
619d77e6a1d2f0ca6b4c889d83a9125f7293a8528f02bad2988892527c9081bd 9184 open-isns_0.103-2_arm64.buildinfo
Files:
626b2145e41d74c03c37d28093d9b56f 2341 net optional open-isns_0.103-2.dsc
e28be8992ea9c59a910f988fe122c6e7 19136 net optional open-isns_0.103-2.debian.tar.xz
ab6a0c86c89ffc33904360812e23bab7 9184 net optional open-isns_0.103-2_arm64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfRrP+tnggGycTNOSXBPW25MFLgMFAmpt6XYACgkQXBPW25MF
LgN6eA/+KT0FBHdiPWBMUILJUkuU5rO84vGY0Ab/koARsgSmEeW6QNWCsjCnJF2d
iusYODCwLscWDs1yLESU0yDGbKc2ye/HSZdOkiaFnReCSkv3prDPjmPs2dexWYkb
gYnJ3Gw+WLwN0prKKWm7lPzqeZAN1PkSf3QRwBXgzpKKtQbsiCmp0xQ518UUA+Sn
5TeLcFALiQzxTmjlR1oJ0qTsVxCMk1qk5y4KwOFENy9v4mN9heEn0Fk4jpBIG4mu
qUNocPcqCY82HuuOKs2908R+ZoGJhVtb0B0Ph86TlRnT0iZeJWeP62gWRDDA6Ahe
Rl42D1SnWGnlx5Wb+lF4sm9W06gOzS3UlFT+jmUO7ffLE/M8cy7d5JmhSvfgUwhF
aMCGuxUX9H0vbdPslaEmvinrb6xar1rc9Z6ajTHsfCPDoAOv59YI2uFBRsoQo7R+
zjHSGPJG42mMIF/OU1jegfFDhfxx9yg2TdnmuB482jhQSXUjCaua29WRqR1S90u1
/w4z6kq1QBdAOQiXwS85xYvQVCSDa7xYlH3HQhCgK0ywSLXUfo3GlmysLKXbmjEb
YPnaMLz5bleG4y10kBDGCODgLgr1VjHlyb3eb5RvfiMVvpRGX6g76wVlSqQvES5q
HzVrvB9nO7DOMkJROq+W4SAD9O4uKPQIOYIqxxLeE1Qf7PjzrYk=
=+0Dy
-----END PGP SIGNATURE-----
Hi Chris, Thanks for the qick turnaround! I have done so, and thanks for having filled the trixie-pu bug already. Regards, Salvatore