[Parted-maintainers] Bug#1148169: parted: CVE-2026-89085 CVE-2026-89088

Carlos Henrique Lima Melara charles at debian.org
Tue Oct 6 04:20:05 BST 2026


Hi parted maintainers,

Thanks for keeping parted up-to-date in Debian!

On Thu, Sep 17, 2026 at 08:32:14PM +0200, Salvatore Bonaccorso wrote:
> 
> The following vulnerabilities were published for parted.
> 
> CVE-2026-89085[0]:
> | heap buffer overflow in _init_fats / fat_table_read
> 
> 
> CVE-2026-89088[1]:
> | heap buffer overflow in duplicate_legacy_root_dir
> 
> 
> If you fix the vulnerabilities please also make sure to include the
> CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

I'm working on these two CVEs for LTS and would like to help fixing them
on trixie too if it's okay for you. Code did not change a lot between
3.6 and 3.7.13 so no backport was needed. There is a test included but I
failed to make it run properly with or without the patch. As a better
regression test tool, I've uploaded to debusine [1] and pushed the
proposed changes to my fork [2], if it's fine for you, I'd love to have
trixie's [2] and bookworm's [3] version in the official git repo (and
hopefully I did everything right with git-dpm :-)

Cheers,
Charles

[1] https://debusine.debian.net/debian/developers/work-request/1425201/
[2] https://salsa.debian.org/charles/parted/-/commits/debian/trixie
[3] https://salsa.debian.org/charles/parted/-/commits/debian/bookworm



More information about the Parted-maintainers mailing list