#1146131 trixie-pu: package binwalk/2.4.3+dfsg1-2+deb13u1

#1146131#5
Date:
2026-08-30 08:46:58 UTC
From:
To:
Dear Release Managers,

I would like to close this bug regarding trixie through p-u:
https://bugs.debian.org/1136010

[ Reason ]
This fixes CVE-2026-7179 for trixie.

[ Impact ]
A path traversal vulnerability exists in binwalk up to 2.4.3 which can
be escalated to remote code execution. The attack can only be performed
from a local environment.
In Debian we are currently stuck to upstream version 2.4.3 for upstream
switched from Python to Rust with version 3.x.x requiring whole new
packaging at Debian's end.

[ Tests ]
I tested the code from the patch manually in a python console to verify
it does what it is supposed to.
I ran the autopkgtests locally with success.

[ Risks ]
I consider the risks nil as the patch is the same applied in unstable,
plus unstable and stable base on the same upstream version.

[ Checklist ]
  [*] *all* changes are documented in the d/changelog
  [*] I reviewed all changes and I approve them
  [*] attach debdiff against the package in (old)stable
  [*] the issue is verified as fixed in unstable