Bug#1143852: trixie-pu: package glib2.0/2.84.4-3~deb13u4
Simon McVittie
smcv at debian.org
Fri Aug 7 11:40:20 BST 2026
Package: release.debian.org
Severity: normal
Tags: trixie d-i
X-Debbugs-Cc: glib2.0 at packages.debian.org, team at security.debian.org, debian-boot at lists.debian.org
Control: affects -1 + src:glib2.0
User: release.debian.org at packages.debian.org
Usertags: pu
[ Reason ]
Fix non-urgent security issues
- CVE-2026-58010
- CVE-2026-58011
- CVE-2026-58012
- CVE-2026-58013
- CVE-2026-58014
- CVE-2026-58015
- CVE-2026-15588
- CVE-2026-58016
[ Impact ]
If not accepted, 8 no-DSA security issues remain unfixed. The proposed
patches also fix some issues that were reported upstream as potential
security vulnerabilities, but were classified as non-security because
they are only reachable if relevant APIs are used incorrectly (passing
non-UTF-8 to functions that require a valid UTF-8 argument).
[ Tests ]
A Debian 13 GNOME desktop and laptop still operate normally. New
automated test coverage is included for the fixed issues, and passes at
build-time and under autopkgtest.
[ Risks ]
All changes to upstream code are targeted, and are straightforward
backports of reviewed upstream changes. The patches applied cleanly
without conflicts, and the only backport-specific changes I had to make
were to add #include <stdint.h> in a few places (GLib ≥ 2.88 already
includes that header globally, but older GLib did not).
The only packaging change was to disable a failing Salsa-CI job (the
uscan check), which has no impact on the built binaries. This
stable-branch is old enough that upstream is no longer making releases
from it, so we will never need to run uscan anyway.
Any of the changes should be straightforward to revert if there's a
problem.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
(filtered to exclude redundant patch content)
[x] the issue is verified as fixed in unstable
[ Changes ]
... are described in the (large) changelog entry.
[ Other info ]
Needs d-i ack, for the GTK installer.
CVE-2026-16118 is not addressed here. It hasn't yet been fixed upstream
or in unstable either, and if it was up to me, I would be tempted to
dispute the CVE assignment and treat it as an ordinary bug (I'm having
difficulty thinking of a scenario where the files being parsed would be
attacker-controlled, without the attacker already having arbitrary code
execution some other way).
Thanks,
smcv
-------------- next part --------------
A non-text attachment was scrubbed...
Name: glib2.0_2.84.4-3~deb13u4.diff
Type: text/x-diff
Size: 80632 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gnome-maintainers/attachments/20260807/98946975/attachment-0001.diff>
More information about the pkg-gnome-maintainers
mailing list