- Package:
- src:zookeeper
- Source:
- src:zookeeper
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-09-20 05:35:04 UTC
- Severity:
- normal
- Tags:
Hi,
The following vulnerabilities were published for zookeeper.
CVE-2026-79993[0]:
| The `deleteContainer` opcode (0x14/20) is processed without
| verifying the caller's ACL permissions, allowing any authenticated
| client to delete specific znodes in the data tree regardless of the
| ACL restrictions on the znode or its parent. This opcode is
| considered internal-only and the official client doesn't have API
| for it, but a client that can open a plain TCP session on the
| ZooKeeper client port (2181 by default) - with NO authentication and
| NO ACL permissions - can delete any empty persistent znode
| (including regular persistent nodes, container nodes, and TTL nodes)
| by issuing the raw protocol OpCode deleteContainer (20). The
| deleteContainer request path completely skips both the session check
| and the DELETE ACL check that are enforced by the regular delete
| (OpCode 2) path. This is an authorization bypass / ACL enforcement
| bug. This issue affects Apache ZooKeeper: from 3.9.0 through 3.9.5,
| from 3.8.0 through 3.8.6. Users are recommended to upgrade to
| version 3.9.6 or 3.8.7, which fixes the issue.
CVE-2026-84439[1]:
| When audit logging is enabled (zookeeper.audit.enable=true), an
| unauthenticated attacker can inject arbitrary fields into Apache
| ZooKeeper's audit log by sending a digest authentication request
| with tab characters (\t) embedded in the username. Because the audit
| log uses tab-separated key=value format, the injected tabs are
| parsed as legitimate field separators, allowing the attacker to
| spoof audit results (e.g., injecting result=success), forge
| operation types, and corrupt forensic evidence. A log injection
| vulnerability in Apache ZooKeeper allows a client that can
| call setACL to inject forged key-value fields
| into zookeeper_audit.log. When audit logging is enabled, the server
| serializes attacker-controlled digest ACL ids into the acl= audit
| field without escaping tab characters. Because audit events are
| emitted as tab-separated key=value records, a crafted ACL id can
| make one successful setAcl event appear to contain forged fields
| such as operation=delete and znode=/forged. This undermines the
| integrity of downstream audit parsing, alerting, and incident
| response. This issue affects Apache ZooKeeper: from 3.9.0 through
| 3.9.5, from 3.8.0 through 3.8.6. Users are recommended to upgrade
| to version 3.9.6 or 3.8.7, which fixes the issue.
CVE-2026-84501[2]:
| An unauthenticated attacker can inject arbitrary fake log lines into
| Apache ZooKeeper's operational log by sending a crafted
| add_auth("ensemble", ...) request containing newline characters
| (\n). When the ensemble name doesn't match,
| EnsembleAuthenticationProvider.handleAuthentication() logs the raw,
| unsanitized name via LOG.warn(). Because SLF4J's {} placeholder
| preserves embedded newlines, the attacker can forge complete log
| entries — with arbitrary timestamps, log levels, class names, and
| messages — that are visually indistinguishable from genuine
| ZooKeeper log output. This issue affects Apache ZooKeeper: from
| 3.9.0 through 3.9.5, from 3.8.0 through 3.8.6. Users are
| recommended to upgrade to version 3.8.7 or 3.9.6, which fixes the
| issue.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-79993
https://www.cve.org/CVERecord?id=CVE-2026-79993
[1] https://security-tracker.debian.org/tracker/CVE-2026-84439
https://www.cve.org/CVERecord?id=CVE-2026-84439
[2] https://security-tracker.debian.org/tracker/CVE-2026-84501
https://www.cve.org/CVERecord?id=CVE-2026-84501
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
We believe that the bug you reported is fixed in the latest version of
zookeeper, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1148409@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
tony mancill <tmancill@debian.org> (supplier of updated zookeeper package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 19 Sep 2026 16:27:19 -0700
Source: zookeeper
Architecture: source
Version: 3.9.6-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: tony mancill <tmancill@debian.org>
Closes: 1148409
Changes:
zookeeper (3.9.6-1) unstable; urgency=medium
.
* New upstream version 3.9.6 (Closes: #1148409)
- Address CVE-2026-79993
- Address CVE-2026-84439
- Address CVE-2026-84501
- zookeeper-contrib-loggraph is no longer distributed by upstream
* Refresh patches for new upstream release
* Strip jdk8 classifier field from jline dependency in POM
* Update slf4j Build-Dep to use libslf4j2-java
* Bump Standards-Version to 4.7.4
Checksums-Sha1:
e77c5517aaebb3316802ecf4f866fcfb7b66f6cf 3794 zookeeper_3.9.6-1.dsc
ca22b99fd0c371f5cf10aa6e3b9d638377365c1c 4597557 zookeeper_3.9.6.orig.tar.gz
4278dbc3e94ae207a6e421cf069d5df4ef0b233f 858 zookeeper_3.9.6.orig.tar.gz.asc
ac9f9a71401e973fe7aa4a272de551cf947b5550 92340 zookeeper_3.9.6-1.debian.tar.xz
a18f6c57cae558ed6ed4c59ae0a93720749c6b0d 24207 zookeeper_3.9.6-1_amd64.buildinfo
Checksums-Sha256:
74b3dfa2e2fc406e212acf4d077cef3cc2ea070e41bf2467148785d90089abab 3794 zookeeper_3.9.6-1.dsc
9277edd177f795c68b3a92cb411a79076b12ad3184fbf900c0d7cec9a0a52e0a 4597557 zookeeper_3.9.6.orig.tar.gz
16518f82fde82132622b78ee975f5c1d12797d64aab895233617cf3e27c0b369 858 zookeeper_3.9.6.orig.tar.gz.asc
dd97d4d31cf7a5cd3505408e4df544fb1416fc69023f4b56b42b26b4ad449027 92340 zookeeper_3.9.6-1.debian.tar.xz
f550caef7c04e5d63c17ae50baa155366f92e028e2bf0817facb3893d09262d3 24207 zookeeper_3.9.6-1_amd64.buildinfo
Files:
d2cbd4702e7bd177262d644599476820 3794 java optional zookeeper_3.9.6-1.dsc
e28f84b98ee099b53357ec05ff89dbab 4597557 java optional zookeeper_3.9.6.orig.tar.gz
45eb24db928384ee54f885d1d2cf90c4 858 java optional zookeeper_3.9.6.orig.tar.gz.asc
8a092376687a9e3e0c6b39c76f85c34b 92340 java optional zookeeper_3.9.6-1.debian.tar.xz
a770ec9b01050db2a5936dfaa02fa0a2 24207 java optional zookeeper_3.9.6-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEE5Qr9Va3SequXFjqLIdIFiZdLPpYFAmqva1YUHHRtYW5jaWxs
QGRlYmlhbi5vcmcACgkQIdIFiZdLPpblshAA1timgKrof2ly9M1qAg/LeYGE7Ysl
OFJcdwrhLcXZeInlYG0LZDF6y1nxOclnTmXas1yraNwKUNX/BhkA4ZoOJ0Tb1kKl
ZO+vNknacfVq8/EVm4hq+W3lMrHcIzMu0Hp423sNOyZFjBOwoVOM2aLdkCG1L05z
YblW83Gb7r5x7a57z5k4cnmvBaC69fGVS+NiQV18/Iahr8lhQTlK+cjzgG6K51/x
VZMLbdG7ofb9r/rDxF+Fbl0rONDI+RQe4P2ob6aYluihnFATNyn2mB61aNv+E87h
NvuGADZz5kpi94KmslfY9817iEQKZbIM3dAI+Sw0f/v8PQjZbTyfZ7no4ymUHdq2
S5IWLjA66r+f1DTodKXaVBTwqb+MVgvGGwbGj6YJwrNhEWFvHI5AcMpduceTfTSB
DmalgvmmGMSTtmCU8V5YCo38K1UM/hAVRlN8qxMtCFfsoLscsqZJb54ZCw+dyGUd
h2OuLyi56uw6EKMA0DZNcYbqFUkP8KnbV7mdOrQS0myp7v2RpL7qcd9s5YPkutaI
ITUrfQyD+uFYFxTRX7VegB6Zl0w+okBsC0GapT5glZkr4O/FM3Bqd+b1oGgca5vM
59JvRl2uBt4Kt/jGTx4NFQIU0Wm/x9rqvrr2TJTcfwANoa5tMfPGpdRtjlPFbDYV
IB+DalFGP3gDTYY=
=elrD
-----END PGP SIGNATURE-----