#1146705 openslide: CVE-2026-54604

Package:
src:openslide
Source:
src:openslide
Submitter:
Moritz Mühlenhoff
Date:
2026-09-06 10:01:01 UTC
Severity:
normal
Tags:
#1146705#5
Date:
2026-09-04 16:10:12 UTC
From:
To:
Hi,

The following vulnerability was published for openslide.

CVE-2026-54604[0]:
https://github.com/openslide/openslide/security/advisories/GHSA-f734-jv98-5677



If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-54604
https://www.cve.org/CVERecord?id=CVE-2026-54604

Please adjust the affected versions in the BTS as needed.

#1146705#14
Date:
2026-09-06 09:40:20 UTC
From:
To:
Hi Moritz,

Moritz Mühlenhoff, on 2026-09-04:

Thanks for the reminder and my apologies for the delay: this was
already documented via #1099727 about upgrading to 4.0.1.  Fix
to Debian unstable stalled on needing to transition openslide,
which I only started coordinating yesterday via #1146803.  Cogs
are now in motion and the issue should be resolved in forky in a
couple of days.  If I parse correctly advisories, this should
not be a problem in trixie and older, for as long as the tiff
library is not bumped to 4.7.1 or later.

Have a nice day,  :)

#1146705#19
Date:
2026-09-06 09:59:14 UTC
From:
To:
Thanks, I've updated the Debian security tracker.

Indeed, since 4.7.1 isn't in trixie, we don't need to do anything
for it.

Cheers,
        Moritz