[Debian-med-packaging] Bug#1146705: Bug#1146705: openslide: CVE-2026-54604

Étienne Mollier emollier at debian.org
Sun Sep 6 10:40:20 BST 2026


Control: fixed -1 4.0.1+dfsg-1~0exp2

Hi Moritz,

Moritz Mühlenhoff, on 2026-09-04:
> The following vulnerability was published for openslide.
> 
> CVE-2026-54604[0]:
> https://github.com/openslide/openslide/security/advisories/GHSA-f734-jv98-5677

Thanks for the reminder and my apologies for the delay: this was
already documented via #1099727 about upgrading to 4.0.1.  Fix
to Debian unstable stalled on needing to transition openslide,
which I only started coordinating yesterday via #1146803.  Cogs
are now in motion and the issue should be resolved in forky in a
couple of days.  If I parse correctly advisories, this should
not be a problem in trixie and older, for as long as the tiff
library is not bumped to 4.7.1 or later.

Have a nice day,  :)
-- 
  .''`.  Étienne Mollier <emollier at debian.org>
 : :' :  pgp: 8f91 b227 c7d6 f2b1 948c  8236 793c f67e 8f0d 11da
 `. `'   sent from /dev/pts/3, please excuse my verbosity
   `-
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/debian-med-packaging/attachments/20260906/7dcf36ed/attachment-0001.sig>


More information about the Debian-med-packaging mailing list