- Package:
- src:cockpit
- Source:
- src:cockpit
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-31 13:49:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for cockpit. CVE-2026-76235[0]: | A memory leak flaw was found in cockpit-ws. The login page handler | leaks a heap allocation on every unauthenticated request that | carries a CockpitLang cookie, allowing a remote unauthenticated | attacker to exhaust memory on the host and cause a denial of | service. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-76235 https://www.cve.org/CVERecord?id=CVE-2026-76235 [1] https://github.com/cockpit-project/cockpit/pull/23633 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
cockpit, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144975@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Martin Pitt <mpitt@debian.org> (supplier of updated cockpit package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 21 Aug 2026 06:22:23 +0200
Source: cockpit
Architecture: source
Version: 366-1
Distribution: unstable
Urgency: medium
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Closes: 1144975
Changes:
cockpit (366-1) unstable; urgency=medium
.
* New upstream release:
- Networkmanager: Don't activate new network connections by default
- Networkmanager: Navigate to details page after creation
* ws: Free "language" string also when it comes from the cookie.
Patch backported from ustream main. [CVE-2026-76235] (Closes: #1144975)
Checksums-Sha1:
2ff0b5a6f12cee3b936cf25dc4db0c1c9c22a149 3241 cockpit_366-1.dsc
8a0e49b5b09543f67ceb4720d77747e4630a9355 39356548 cockpit_366.orig-node.tar.xz
02fffc0e694e3ef0b2bf4a2fe56f7fd9471fb7dd 15908636 cockpit_366.orig.tar.xz
7a478730f402b0052f03afb3bbcc5ff36229c38b 26512 cockpit_366-1.debian.tar.xz
7dd30a0d332a463a826e69e1a0c74bacb064e50f 10335 cockpit_366-1_source.buildinfo
Checksums-Sha256:
075ea48ad8ded13ae4b7e1e22e7c8e9198bfa1011b7300715195a2f8459aec91 3241 cockpit_366-1.dsc
e45d9b76ce19e1cfad33dbda3c7ad9c22fa5a29cf94f0492fdab23b46511e093 39356548 cockpit_366.orig-node.tar.xz
bf0a8c37eca303282a85777e049fce67fe2002743fabfb3e85f9de24855b099a 15908636 cockpit_366.orig.tar.xz
447e178def2568d9b90d3a5c3e81be3e964289864de8e25020b3e047d906af25 26512 cockpit_366-1.debian.tar.xz
2d7a912ddfcd963f1b213f503f3f7c5ecfe09a37f3e99abd6052d2b981242094 10335 cockpit_366-1_source.buildinfo
Files:
795e497b18d6757acd714ba38c540980 3241 admin optional cockpit_366-1.dsc
b4f834554ce4d6a2b137f28fc164d20f 39356548 admin optional cockpit_366.orig-node.tar.xz
016d4a5b7fa14a452756dce319715215 15908636 admin optional cockpit_366.orig.tar.xz
02ba28d1a1f95f3a625294aacc70a5ae 26512 admin optional cockpit_366-1.debian.tar.xz
90dfc3da909cac7e8d439f8bf5550b76 10335 admin optional cockpit_366-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmqH0zYACgkQ7nvd5Lhr
VxODchAAoo/h7JxGURnBTcLZofTvuiRDC9UasN+MYGQF0sRjsPEGcTJvIYYCLDaM
GPRWKnIOCPOogui7ckTAIZ3nMfgfo+t4PnBduuaypsKyll+WCmjZGmBOwVND0uHG
GjCqcHobgUtsXCUtuQIVz4num0J7sNM10FkNiuEbwCxPnWwrFS6XYR2+EQXwu+R0
F94D9HnI3eaFI1rM8tz8I0l/9TIHCeHZx/n2VSWdAlpimzdx5ZfklXR/lTnSvJM6
o5vCoTiTJcbezz2lBMRP+zXfRsKfzCOrZJdmRcYyciyxMgyrUEncbs3p2Nfcc0TI
S8DFnFrSXbCHJ41olaLZYmeh9Gd+mzTem+BpdL+sVH/xm0r17Od358hbGmqv3fvf
Nzm0bCiInggt3MfQYwf5DD/SABgAkKM4u6POxFMqtsBjv5vOwvW5M+nXlVJ09JGF
aHKObSdH7uOCpEOnQ8463d4mwnL1yqUte8yMEX3iz05eZ65CslpdeTh8tfYEjXR1
NIrn+KRk9VhmA8GV+7N+i/cAaaAVd/pg5qoTPtr35LthYQ3xD1xK18mDGk3pAFXP
im18K9dGIvQhFx1RIBh8k2tc0Ln1xbwl8spdCNoU6t7sIb67k50LXHxHPIw3Sgyz
152g2zbflvoc+/EK5OX68atWQJ8e1eJCpFk68Zth3T0x5RoIhVo=
=XiPa
-----END PGP SIGNATURE-----
Buongiorno Salvatore, Salvatore Bonaccorso [2026-08-21 6:07 +0200]: I prepared a trixie security update, attached debdiff. Please let me know if/when to upload. Thanks! Pitti
We believe that the bug you reported is fixed in the latest version of
cockpit, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144975@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Martin Pitt <mpitt@debian.org> (supplier of updated cockpit package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 25 Aug 2026 08:35:13 +0200
Source: cockpit
Architecture: source
Version: 337-1+deb13u2
Distribution: trixie-security
Urgency: medium
Maintainer: Utopia Maintenance Team <pkg-utopia-maintainers@lists.alioth.debian.org>
Changed-By: Martin Pitt <mpitt@debian.org>
Closes: 1144975
Changes:
cockpit (337-1+deb13u2) trixie-security; urgency=medium
.
* ws: Free "language" string also when it comes from the cookie.
Fixes remote unauthenticated DoS and huge memory usage (throttled at 75%
and capped at 90% via systemd slice resource control).
[CVE-2026-76235] (Closes: #1144975)
* pkg/systemd: robustify argument quoting. Fixes arbitrary command
execution via crafted links to the system logs user interface.
Patch backported from upstream commit e3a47d70f99a0d, and hand-applied in
debian/rules to the built bundle, as this branch does not yet rebuild
the bundles during package build. [CVE-2026-4802]
has no effect; instead apply the equivalent change to the shipped
dist/systemd/logs.js.gz via sed in debian/rules.
Checksums-Sha1:
5101f7ee3eacb6266915e79888b2ca5abd7676de 3007 cockpit_337-1+deb13u2.dsc
9a45726c9e5e5078e2d69ec9eac5676171c972bd 14759784 cockpit_337.orig.tar.xz
17a7844eb71db11fd8d667231cb43ca726614796 25428 cockpit_337-1+deb13u2.debian.tar.xz
88ae2f9ad5bb5fc65309dcef077051b403a3e146 11176 cockpit_337-1+deb13u2_source.buildinfo
Checksums-Sha256:
9ba12b9ebdadbcb34d78fd039997e0ef936e98ded322ebf9862fb5224b124def 3007 cockpit_337-1+deb13u2.dsc
df51ef5920fae69e1b435f657376aa93772c0c1720b954a3bac10ebba26bfedf 14759784 cockpit_337.orig.tar.xz
c5fc9d0f56a16d5af3fb6ecd556d174664fbd7f5abe26d470bb4d7f147f0f55f 25428 cockpit_337-1+deb13u2.debian.tar.xz
a98671103fe4b5ce1b71a1ca0b267d4dc19888cd2a1b6425af81abd2a0c9bc6c 11176 cockpit_337-1+deb13u2_source.buildinfo
Files:
5f68ce133c1b614da5a41b48fca7f24d 3007 admin optional cockpit_337-1+deb13u2.dsc
9c03bb1048d7bfa99bc5e3ca953457e8 14759784 admin optional cockpit_337.orig.tar.xz
3d8b239060116ad0609b45379478864f 25428 admin optional cockpit_337-1+deb13u2.debian.tar.xz
b0b9c2767f0c29ca0e8cdda94441d80b 11176 admin optional cockpit_337-1+deb13u2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmqP2QAACgkQ7nvd5Lhr
VxPCmxAAl8vlCHqXqwZPwTa9EZ4ekGs5PPiQiI9m01tjOtagq19AW7Gvi6kV2ZQn
G8zMyp7jO4IUjYkxcy06m2Ji2COjOzSZmTtn5Sv/gi3swkbT5sC9hfxSE2o4bT6o
VMs5ISyEpiuZliooArktWHq15GumQXvE6kM90yDe1R0XcxmCdgr9PQ6ppH89Pd+F
MdE8CMw3Ytz8vNiRCAAx1Mx+7zzrevGwa2uwhxsKlMe2QKDYC8qJyJHCpsVAPZEX
QVb+DUKrujo4z2QxIZNKnBjaoTOd5GP3XL+lk2HcmB0UwW1J5FHekoxxQwFxgTsR
E+3EuLQD5ynjMQr2ksZD7n7tPPddltCDDl+TsaKFVjTlOLXGSMhLv9PuwEKPIrS+
Edkluv+C19cpRSG5M0t9ZIFe2bAljufhchvDZS+cgMgn/EK9F05oTY3LgB3bHoLW
U2GWieiqgViUNozxCRhcCJ7h02rV3Fa9CYagQdb2KVFBcYkNc9th3E7QgnS9hILE
kXuIeWU905NECwZKIwNHPbEfh/qWgpd4MxFxFPCepQdFbQCJbNEX7O0d1TSaR0X/
ulcuH7RBwWuOBjo9oB0uCVB76Frgj7M2pnrjmQqL1SyDwGo2iR+9YUQ8XUvth0wL
vBjAV7BIqgGfRocX6Q7zzKqbuxuuDWM1UNYcdED6Tx7CWKCNr+I=
=vBwn
-----END PGP SIGNATURE-----