[Parted-maintainers] Bug#1148169: parted: CVE-2026-89085 CVE-2026-89088
Colin Watson
cjwatson at debian.org
Fri Oct 9 13:43:30 BST 2026
On Tue, Oct 06, 2026 at 12:20:05AM -0300, Carlos Henrique Lima Melara wrote:
>On Thu, Sep 17, 2026 at 08:32:14PM +0200, Salvatore Bonaccorso wrote:
>> The following vulnerabilities were published for parted.
>>
>> CVE-2026-89085[0]:
>> | heap buffer overflow in _init_fats / fat_table_read
>>
>>
>> CVE-2026-89088[1]:
>> | heap buffer overflow in duplicate_legacy_root_dir
>>
>>
>> If you fix the vulnerabilities please also make sure to include the
>> CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
>
>I'm working on these two CVEs for LTS and would like to help fixing them
>on trixie too if it's okay for you. Code did not change a lot between
>3.6 and 3.7.13 so no backport was needed. There is a test included but I
>failed to make it run properly with or without the patch. As a better
>regression test tool, I've uploaded to debusine [1] and pushed the
>proposed changes to my fork [2], if it's fine for you, I'd love to have
>trixie's [2] and bookworm's [3] version in the official git repo (and
>hopefully I did everything right with git-dpm :-)
Your branches look OK to me. Thanks for working on this!
Would you be OK with me just adding you to parted-team? I'd be happy to
do that, and then you can merge things yourself.
--
Colin Watson (he/him) [cjwatson at debian.org]
More information about the Parted-maintainers
mailing list