#1144734 trixie-pu: package goaccess/1:1.9.3-1+deb13u1

#1144734#5
Date:
2026-08-18 11:36:23 UTC
From:
To:
[ Reason ]
This update includes 3 upstream patches fixing 3 CVEs published for
goaccess.

[ Impact ]
goaccess is a web server log analysis tool. Specially crafted requests
can explore those vulnerabilities and cause it to overwrite memory or
crash.

[ Tests ]
There is no regression in the (admittedly simple) autopkgtests.

[ Risks ]
The changes were cherry-picked from upstream, applied cleanly over the
trixie branch, and are very targeted and localized.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
  [x] the issue is verified as fixed in unstable

[ Changes ]
The main change is adding 3 upstream patches cherry-picked from the
latest upstream release. The change to debian/salsa-ci.yml is necessary
to prevent a failure on Salsa CI related to uscan (debian/watch is fixed
in the sid/forky version of the package).

[ Other info ]
This was marked as no-DSA by the Security team so I'm going with a
stable update.

I'm attaching both the full diff against the version in trixie, and the
actual patches since those are easier to read than the diff-in-diff
version in the full diff.

#1144734#12
Date:
2026-09-04 11:21:34 UTC
From:
To:
Control: tags -1 + confirmed

Please go ahead.

Regards,

Adam

#1144734#19
Date:
2026-09-05 14:49:21 UTC
From:
To:
Uploaded.
#1144734#24
Date:
2026-09-05 17:23:57 UTC
From:
To:
package release.debian.org
tags 1144734 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: goaccess
Version: 1.9.3-1+deb13u1

Explanation: fix out of bounds write issue [CVE-2026-54715]; fix denial of service issue [CVE-2026-55768 CVE-2026-55777]

#1144734#29
Date:
2026-09-05 17:23:57 UTC
From:
To:
package release.debian.org
tags 1144734 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: goaccess
Version: 1.9.3-1+deb13u1

Explanation: fix out of bounds write issue [CVE-2026-54715]; fix denial of service issue [CVE-2026-55768 CVE-2026-55777]

#1144734#34
Date:
2026-09-12 08:05:41 UTC
From:
To:
This update was released as part of 13.7.