#1148169 parted: CVE-2026-89085 CVE-2026-89088

Package:
src:parted
Source:
src:parted
Submitter:
Salvatore Bonaccorso
Date:
2026-10-09 13:04:02 UTC
Severity:
normal
Tags:
#1148169#5
Date:
2026-09-17 18:32:14 UTC
From:
To:
Hi,

The following vulnerabilities were published for parted.

CVE-2026-89085[0]:
| heap buffer overflow in _init_fats / fat_table_read


CVE-2026-89088[1]:
| heap buffer overflow in duplicate_legacy_root_dir


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-89085
https://www.cve.org/CVERecord?id=CVE-2026-89085
[1] https://security-tracker.debian.org/tracker/CVE-2026-89088
https://www.cve.org/CVERecord?id=CVE-2026-89088
[2] https://alioth-lists.debian.net/pipermail/parted-devel/2026-September/006032.html
[3] https://gitweb.git.savannah.gnu.org/gitweb/?p=parted.git;a=commit;h=73301c6915781c2eee66d0b1cc9d41a70bf901d6

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1148169#10
Date:
2026-09-25 09:33:59 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
parted, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1148169@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Colin Watson <cjwatson@debian.org> (supplier of updated parted package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Fri, 25 Sep 2026 10:10:23 +0100
Source: parted
Architecture: source
Version: 3.8-2
Distribution: unstable
Urgency: medium
Maintainer: Parted Maintainer Team <parted-maintainers@alioth-lists.debian.net>
Changed-By: Colin Watson <cjwatson@debian.org>
Closes: 1148169
Changes:
 parted (3.8-2) unstable; urgency=medium
 .
   * Reupload pointing dgit to the correct upstream tag.
 .
 parted (3.8-1) unstable; urgency=medium
 .
   * New upstream release:
     - CVE-2026-89085, CVE-2026-89088: Catch errors triggered by bad FAT
       metadata (closes: #1148169).
Checksums-Sha1:
 79919b45121c04c7fa0dcb8834e5ea25da9534c1 2978 parted_3.8-2.dsc
 9c5179eb9116f7718c4c7cab08d3c2643ebbcfcd 52872 parted_3.8-2.debian.tar.xz
 d97491f2fe51f9fc1e4e5f7a0e68d90f875f8c72 9880912 parted_3.8-2.git.tar.xz
 afcad79fa428660bec59469235723dc7b7093333 17712 parted_3.8-2_source.buildinfo
 8484cf0c6b801bbf5b1918de27d28998af05673e 2072636 parted_3.8.orig.tar.xz
Checksums-Sha256:
 29a231c59b022c36f77fb7ba548fa23fb4e9a9f9189795fa55de212d15c5e648 2978 parted_3.8-2.dsc
 468ad533a54b84d49d18247e9a922092556836d5fb8ca391f9251e1e4c6a87a5 52872 parted_3.8-2.debian.tar.xz
 b0f43e39fdbe4045e3c475ec5417603cdff8977cf3ece068f799029ff21bb94e 9880912 parted_3.8-2.git.tar.xz
 c222a803aeefb7f6faa116b2a20249227fc02028711f9ad81ced524c425effaa 17712 parted_3.8-2_source.buildinfo
 9b5713ad52559e62cabc62a3c5f9ba12ab9d4c0aaa27fcabf56778901bdce1a3 2072636 parted_3.8.orig.tar.xz
Files:
 0d5e0ff8bbb29b5f958532ff64df8061 2978 admin optional parted_3.8-2.dsc
 b61a214c3d8117a4ec6a32091725c0d6 52872 admin optional parted_3.8-2.debian.tar.xz
 992684972817c4ebf04db35634bb45b4 9880912 admin optional parted_3.8-2.git.tar.xz
 aa120fd96b54b3a2b293d732509611aa 17712 admin optional parted_3.8-2_source.buildinfo
 4c31e78dcc5e24bc380a39bb1f9310c3 2072636 admin optional parted_3.8.orig.tar.xz
Git-Tag-Info: tag=98decabcabdc8fabb95d5e53c31ae99dde86e15b fp=ac0a4ff12611b6fccf01c111393587d97d86500b
Git-Tag-Tagger: Colin Watson <cjwatson@debian.org>
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmq2OucACgkQYG0ITkaD
wHlIkQ/+Na4pKVJCfjre3PapDjqtmdYKEaVA3EcMQ7kVNiMRHHGlJVykBMe7G07o
fJw5P1WgLTw1k9BkKK5fiHjiWpUgjjP2mIsBBzjNnUeDA7ZYURqiUZgFY/AZXY2b
CYnIVEDA6xh5kWeD26r280n/oLmwRYqDEq5j5Y5pXFJI3vO+BPCvpSL6BXK5TJq9
dEoEkltLAX3iYW6pnyAy7FrOZmyn8zf0ZwOrZQ6j2GMjacFl7nrDDHJ745qGAE40
kGEkHNmWS3Y/VT9/Hm8JlXS1j9IoAb8TuVCYwAIrSASMnxeez1C8ZU4c6ZQgljdo
k2/F3F9DjdZbWSEd0NZL6FMtox9EhQHW9pAtUxy3f1Pe0phzDnL+v39nUOJ2lpsI
cqYUNT1M6MYkB69WhT6iIWlWOir9FuXhSCKjIwAMB9Pqj7+Z3O028KJ4Kk1YHB5S
K70UJSeRZYizz67IjH6KWJ0B89wR2eFzpsiEruzx16JUPBEuPV6+H14w4yiVv03p
7Mva3eEHncOyDBtDj02k471Cl6CGQ480gXt2DybeXuspbb5N2JyV2xW3SrCjo80H
vdeL+wPm15OrlAEkLaDR8qICOzNZCA8jLoMeDkCARuAAmup6+a8Qi3ktBIZPVnfc
gJ0AVqyLR8HtWkr7ApA8ARM/sQQxxb/H9Y0rUnzjKVAJttjfdkg=
=GS69
-----END PGP SIGNATURE-----

#1148169#15
Date:
2026-10-06 03:20:05 UTC
From:
To:
Hi parted maintainers,

Thanks for keeping parted up-to-date in Debian!

I'm working on these two CVEs for LTS and would like to help fixing them
on trixie too if it's okay for you. Code did not change a lot between
3.6 and 3.7.13 so no backport was needed. There is a test included but I
failed to make it run properly with or without the patch. As a better
regression test tool, I've uploaded to debusine [1] and pushed the
proposed changes to my fork [2], if it's fine for you, I'd love to have
trixie's [2] and bookworm's [3] version in the official git repo (and
hopefully I did everything right with git-dpm :-)

Cheers,
Charles

[1] https://debusine.debian.net/debian/developers/work-request/1425201/
[2] https://salsa.debian.org/charles/parted/-/commits/debian/trixie
[3] https://salsa.debian.org/charles/parted/-/commits/debian/bookworm

#1148169#20
Date:
2026-10-09 12:43:30 UTC
From:
To:
Your branches look OK to me.  Thanks for working on this!

Would you be OK with me just adding you to parted-team?  I'd be happy to
do that, and then you can merge things yourself.