- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Emmanuel Arias
- Date:
- 2026-09-12 08:07:38 UTC
- Severity:
- normal
- Tags:
[ Reason ] Fixing CVE-2026-59884, CVE-2026-59885 and, CVE-2026-59886 [ Impact ] Denial of service, cpu and memory exhaustion [ Tests ] Build it in debusine https://debusine.debian.net/debian/developers/work-request/1108490/ [ Risks ] No issues as I can see, patches are simple, upstream added unittests. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable
Control: tags -1 + confirmed Please go ahed. Regards, Adam
Hello Adam, Uploaded, thanks!
package release.debian.org tags 1145581 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: pyasn1 Version: 0.6.1-1+deb13u3 Explanation: fix denial of service issues [CVE-2026-59884 CVE-2026-59885 CVE-2026-59886]
package release.debian.org tags 1145581 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: pyasn1 Version: 0.6.1-1+deb13u3 Explanation: fix denial of service issues [CVE-2026-59884 CVE-2026-59885 CVE-2026-59886]
This update was released as part of 13.7.