#1143852 trixie-pu: package glib2.0/2.84.4-3~deb13u4

#1143852#5
Date:
2026-08-07 10:40:20 UTC
From:
To:
[ Reason ]
Fix non-urgent security issues
- CVE-2026-58010
- CVE-2026-58011
- CVE-2026-58012
- CVE-2026-58013
- CVE-2026-58014
- CVE-2026-58015
- CVE-2026-15588
- CVE-2026-58016

[ Impact ]
If not accepted, 8 no-DSA security issues remain unfixed. The proposed
patches also fix some issues that were reported upstream as potential
security vulnerabilities, but were classified as non-security because
they are only reachable if relevant APIs are used incorrectly (passing
non-UTF-8 to functions that require a valid UTF-8 argument).

[ Tests ]
A Debian 13 GNOME desktop and laptop still operate normally. New
automated test coverage is included for the fixed issues, and passes at
build-time and under autopkgtest.

[ Risks ]
All changes to upstream code are targeted, and are straightforward
backports of reviewed upstream changes. The patches applied cleanly
without conflicts, and the only backport-specific changes I had to make
were to add #include <stdint.h> in a few places (GLib ≥ 2.88 already
includes that header globally, but older GLib did not).

The only packaging change was to disable a failing Salsa-CI job (the
uscan check), which has no impact on the built binaries. This
stable-branch is old enough that upstream is no longer making releases
from it, so we will never need to run uscan anyway.

Any of the changes should be straightforward to revert if there's a
problem.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
      (filtered to exclude redundant patch content)
  [x] the issue is verified as fixed in unstable

[ Changes ]
... are described in the (large) changelog entry.

[ Other info ]
Needs d-i ack, for the GTK installer.

CVE-2026-16118 is not addressed here. It hasn't yet been fixed upstream
or in unstable either, and if it was up to me, I would be tempted to
dispute the CVE assignment and treat it as an ordinary bug (I'm having
difficulty thinking of a scenario where the files being parsed would be
attacker-controlled, without the attacker already having arbitrary code
execution some other way).

Thanks,
    smcv

#1143852#12
Date:
2026-08-08 14:02:22 UTC
From:
To:
Hi,

Simon McVittie <smcv@debian.org> (2026-08-07):

Please go ahead, thanks; bonus points if you let me know once the
package gets uploaded/accepted so that I can run a few tests ahead
of point release preparations.


Cheers,

#1143852#17
Date:
2026-08-08 15:37:09 UTC
From:
To:
I already uploaded to the queue, so the rest is up to the SRMs, unless
they ask for changes.

I've put functionally equivalent test-builds in
https://people.debian.org/~smcv/13.7/glib2.0-deb13u4/ in case that's
helpful (the only difference is in d/changelog).

GLib upstream has now fixed CVE-2026-16118 as well, so I might do a
(much smaller!) ~deb13u5 later to incorporate that - but I'd like to let
these fixes migrate to testing first, and then do a new unstable upload,
before preparing ~deb13u5.

     smcv

#1143852#22
Date:
2026-08-08 16:02:47 UTC
From:
To:
Simon McVittie <smcv@debian.org> (2026-08-08):

Perfect, going for that on my own was my backup plan, that spares me a
few cycles; thanks!

Makes sense.


Cheers,