Dear Release Managers,
I would like to close this bug regarding trixie through p-u:
https://bugs.debian.org/1136010
[ Reason ]
This fixes CVE-2026-7179 for trixie.
[ Impact ]
A path traversal vulnerability exists in binwalk up to 2.4.3 which can
be escalated to remote code execution. The attack can only be performed
from a local environment.
In Debian we are currently stuck to upstream version 2.4.3 for upstream
switched from Python to Rust with version 3.x.x requiring whole new
packaging at Debian's end.
[ Tests ]
I tested the code from the patch manually in a python console to verify
it does what it is supposed to.
I ran the autopkgtests locally with success.
[ Risks ]
I consider the risks nil as the patch is the same applied in unstable,
plus unstable and stable base on the same upstream version.
[ Checklist ]
[*] *all* changes are documented in the d/changelog
[*] I reviewed all changes and I approve them
[*] attach debdiff against the package in (old)stable
[*] the issue is verified as fixed in unstable