Bug#1143852: trixie-pu: package glib2.0/2.84.4-3~deb13u4

Simon McVittie smcv at debian.org
Fri Aug 7 11:40:20 BST 2026


Package: release.debian.org
Severity: normal
Tags: trixie d-i
X-Debbugs-Cc: glib2.0 at packages.debian.org, team at security.debian.org, debian-boot at lists.debian.org
Control: affects -1 + src:glib2.0
User: release.debian.org at packages.debian.org
Usertags: pu

[ Reason ]
Fix non-urgent security issues
- CVE-2026-58010
- CVE-2026-58011
- CVE-2026-58012
- CVE-2026-58013
- CVE-2026-58014
- CVE-2026-58015
- CVE-2026-15588
- CVE-2026-58016

[ Impact ]
If not accepted, 8 no-DSA security issues remain unfixed. The proposed 
patches also fix some issues that were reported upstream as potential 
security vulnerabilities, but were classified as non-security because 
they are only reachable if relevant APIs are used incorrectly (passing 
non-UTF-8 to functions that require a valid UTF-8 argument).

[ Tests ]
A Debian 13 GNOME desktop and laptop still operate normally. New 
automated test coverage is included for the fixed issues, and passes at 
build-time and under autopkgtest.

[ Risks ]
All changes to upstream code are targeted, and are straightforward 
backports of reviewed upstream changes. The patches applied cleanly 
without conflicts, and the only backport-specific changes I had to make 
were to add #include <stdint.h> in a few places (GLib ≥ 2.88 already 
includes that header globally, but older GLib did not).

The only packaging change was to disable a failing Salsa-CI job (the 
uscan check), which has no impact on the built binaries. This 
stable-branch is old enough that upstream is no longer making releases 
from it, so we will never need to run uscan anyway.

Any of the changes should be straightforward to revert if there's a 
problem.

[ Checklist ]
  [x] *all* changes are documented in the d/changelog
  [x] I reviewed all changes and I approve them
  [x] attach debdiff against the package in (old)stable
      (filtered to exclude redundant patch content)
  [x] the issue is verified as fixed in unstable

[ Changes ]
... are described in the (large) changelog entry.

[ Other info ]
Needs d-i ack, for the GTK installer.

CVE-2026-16118 is not addressed here. It hasn't yet been fixed upstream 
or in unstable either, and if it was up to me, I would be tempted to 
dispute the CVE assignment and treat it as an ordinary bug (I'm having 
difficulty thinking of a scenario where the files being parsed would be 
attacker-controlled, without the attacker already having arbitrary code 
execution some other way).

Thanks,
    smcv
-------------- next part --------------
A non-text attachment was scrubbed...
Name: glib2.0_2.84.4-3~deb13u4.diff
Type: text/x-diff
Size: 80632 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gnome-maintainers/attachments/20260807/98946975/attachment-0001.diff>


More information about the pkg-gnome-maintainers mailing list