- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Simon McVittie
- Date:
- 2026-09-12 08:07:30 UTC
- Severity:
- normal
- Tags:
[ Reason ]
Fix non-urgent security issues
- CVE-2026-58010
- CVE-2026-58011
- CVE-2026-58012
- CVE-2026-58013
- CVE-2026-58014
- CVE-2026-58015
- CVE-2026-15588
- CVE-2026-58016
[ Impact ]
If not accepted, 8 no-DSA security issues remain unfixed. The proposed
patches also fix some issues that were reported upstream as potential
security vulnerabilities, but were classified as non-security because
they are only reachable if relevant APIs are used incorrectly (passing
non-UTF-8 to functions that require a valid UTF-8 argument).
[ Tests ]
A Debian 13 GNOME desktop and laptop still operate normally. New
automated test coverage is included for the fixed issues, and passes at
build-time and under autopkgtest.
[ Risks ]
All changes to upstream code are targeted, and are straightforward
backports of reviewed upstream changes. The patches applied cleanly
without conflicts, and the only backport-specific changes I had to make
were to add #include <stdint.h> in a few places (GLib ≥ 2.88 already
includes that header globally, but older GLib did not).
The only packaging change was to disable a failing Salsa-CI job (the
uscan check), which has no impact on the built binaries. This
stable-branch is old enough that upstream is no longer making releases
from it, so we will never need to run uscan anyway.
Any of the changes should be straightforward to revert if there's a
problem.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
(filtered to exclude redundant patch content)
[x] the issue is verified as fixed in unstable
[ Changes ]
... are described in the (large) changelog entry.
[ Other info ]
Needs d-i ack, for the GTK installer.
CVE-2026-16118 is not addressed here. It hasn't yet been fixed upstream
or in unstable either, and if it was up to me, I would be tempted to
dispute the CVE assignment and treat it as an ordinary bug (I'm having
difficulty thinking of a scenario where the files being parsed would be
attacker-controlled, without the attacker already having arbitrary code
execution some other way).
Thanks,
smcv
Hi, Simon McVittie <smcv@debian.org> (2026-08-07): Please go ahead, thanks; bonus points if you let me know once the package gets uploaded/accepted so that I can run a few tests ahead of point release preparations. Cheers,
I already uploaded to the queue, so the rest is up to the SRMs, unless they ask for changes. I've put functionally equivalent test-builds in https://people.debian.org/~smcv/13.7/glib2.0-deb13u4/ in case that's helpful (the only difference is in d/changelog). GLib upstream has now fixed CVE-2026-16118 as well, so I might do a (much smaller!) ~deb13u5 later to incorporate that - but I'd like to let these fixes migrate to testing first, and then do a new unstable upload, before preparing ~deb13u5. smcv
Simon McVittie <smcv@debian.org> (2026-08-08): Perfect, going for that on my own was my backup plan, that spares me a few cycles; thanks! Makes sense. Cheers,
package release.debian.org tags 1143852 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: glib2.0 Version: 2.84.4-3~deb13u4 Explanation: fix out of bounds access issues [CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014]; fix file content disclosure issue [CVE-2026-58015]; fix denial of service issue [CVE-2026-15588]; fix integer underflow issue [CVE-2026-58016]
package release.debian.org tags 1143852 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: glib2.0 Version: 2.84.4-3~deb13u4 Explanation: fix out of bounds access issues [CVE-2026-58010 CVE-2026-58011 CVE-2026-58012 CVE-2026-58013 CVE-2026-58014]; fix file content disclosure issue [CVE-2026-58015]; fix denial of service issue [CVE-2026-15588]; fix integer underflow issue [CVE-2026-58016]
This update was released as part of 13.7.