#1144106 ostree: GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems

Package:
libostree-1-1
Source:
libostree-1-1
Description:
content-addressed filesystem for operating system binaries (library)
Submitter:
Simon McVittie
Date:
2026-08-11 09:15:02 UTC
Severity:
normal
Tags:
#1144106#5
Date:
2026-08-11 09:12:20 UTC
From:
To:
https://github.com/ostreedev/ostree/security/advisories/GHSA-xppc-j946-vcj7

A vulnerability in libostree allows the operator of a malicious or
compromised OSTree repository to trigger a heap buffer overflow on
32-bit systems. All versions ever shipped by Debian appear to be
affected. There is currently no known CVE ID.

A mitigation is that only 32-bit architectures are affected.

I would very much appreciate it if someone else could take
responsibility for identifying the specific fixes and preparing a
backport to Debian 13.

Thanks,
    smcv