glib2.0_2.84.4-3~deb13u4_source.changes ACCEPTED into proposed-updates->stable-new

Debian FTP Masters ftpmaster at ftp-master.debian.org
Fri Aug 7 12:13:51 BST 2026


Thank you for your contribution to Debian.

Mapping trixie to stable.
Mapping stable to proposed-updates.

Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 07 Aug 2026 10:33:15 +0100
Source: glib2.0
Architecture: source
Version: 2.84.4-3~deb13u4
Distribution: trixie
Urgency: medium
Maintainer: Debian GNOME Maintainers <pkg-gnome-maintainers at lists.alioth.debian.org>
Changed-By: Simon McVittie <smcv at debian.org>
Closes: 1141316 1142835
Changes:
 glib2.0 (2.84.4-3~deb13u4) trixie; urgency=medium
 .
   * Edit previous changelog entry to correlate CVE fixes with upstream
     bug numbers and releases
   * Add patches from upstream 2.86.5 to fix out-of-bounds accesses:
     - d/p/gvariant-Fix-an-off-by-one-error-in-an-offset-comparison.patch:
       Fix a potential out of bounds read by 1 byte
       (CVE-2026-58010, glib#3915 upstream)
     - d/p/gmarkup-Fix-potential-one-byte-overread-in-g_markup_escap.patch:
       Fix a potential out of bounds read by 1 byte when escaping text that
       is not valid UTF-8
       (not considered to be a vulnerability, glib#3916 upstream)
     - d/p/gdatetime-Factor-out-a-couple-of-magic-constants.patch,
       d/p/gdatetime-Add-missing-range-validation-to-g_date_time_add.patch:
       Fix an out of bounds read by up to 2 bytes after parsing an
       out-of-range date
       (CVE-2026-58011, glib#3917 upstream)
     - d/p/gregex-Fix-case-changing-substitutions-with-G_REGEX_RAW.patch:
       Fix a potential buffer overflow when changing the case of an incomplete
       UTF-8 sequence while using G_REGEX_RAW
       (CVE-2026-58012, glib#3918 upstream)
     - d/p/gregex-Fix-use-of-wrong-option-flags-set-for-checking-for.patch,
       d/p/gregex-Rename-the-compile_opts-members-to-clarify-their-t.patch:
       Fix an out-of-bounds read when g_regex_split_full() acts on
       invalid UTF-8
       (not considered to be a vulnerability, glib#3919 upstream)
   * Add patches from upstream 2.88.1 to fix several issues that were reported
     as potential security vulnerabilities:
     - d/p/giochannel-Fix-memcmp-off-the-end-of-the-buffer-with-long.patch:
       Fix out-of-bounds read if a GIOChannel is configured with a long
       line-terminator
       (CVE-2026-58013, glib#3825 upstream)
     - d/p/gkeyfile-Fix-a-one-byte-heap-under-read-with-g_key_file_g.patch:
       Fix out-of-bounds read if a list of locale-dependent strings in a
       GKeyFile is empty
       (CVE-2026-58014, glib#3930 upstream)
     - d/p/gdbusmessage-Fix-types-of-integer-arithmetic-in-message-l.patch:
       Fix an integer overflow that could lead to accepting overly large
       messages on peer-to-peer D-Bus connections
       (no CVE ID, glib#3933 upstream)
     - d/p/gdbusauthmechanismsha1-Validate-cookie-context.patch,
       d/p/gdbusauthmechanismsha1-Improve-validation-of-cookie-ID.patch,
       d/p/gdbusauthmechanism-Expose-client-reject-reason-as-a-new-v.patch,
       d/p/tests-Add-a-unit-test-for-GDBusAuthMechanismSha1-cookie-c.patch:
       Prevent path traversal and file-content disclosure if a D-Bus client
       connects to a malicious peer-to-peer D-Bus server
       (CVE-2026-58015, glib#3931 upstream)
   * Add patch from upstream 2.88.3 fixing a possible denial of service:
     - d/p/gdbusauth-Limit-length-of-lines-read-from-client.patch:
       Fix resource exhaustion if a malicious client can contact a
       GDBusServer
       (CVE-2026-15588, glib#3985 upstream, Closes: #1142835)
   * Add patches from upstream 2.89.0 to harden D-Bus introspection parsing
     - d/p/gdbusintrospection-Add-some-assertions-before-array-deref.patch,
       d/p/tests-Improve-D-Bus-introspection-test-paths.patch,
       d/p/gdbusintrospection-Fix-XML-parser-state-handling-for-node.patch,
       d/p/fuzzing-Add-a-fuzz-test-for-g_dbus_node_info_new_for_xml.patch:
       Avoid a possible integer underflow if parsing malformed D-Bus
       introspection XML sent by a malicious service
       (glib#3932 upstream, CVE-2026-58016, Closes: #1141316)
   * d/salsa-ci.yml: Disable uscan job as not relevant to this stable branch
Checksums-Sha1:
 bdf37b97b5bdfb928ec4641bde59cf152c024dea 5004 glib2.0_2.84.4-3~deb13u4.dsc
 34c62ab7e2cf9b70090d0b9671546f9aba4badc8 171232 glib2.0_2.84.4-3~deb13u4.debian.tar.xz
 dd9451045c58bc9d1d7ac93fba1c1383b4216df6 7787 glib2.0_2.84.4-3~deb13u4_source.buildinfo
Checksums-Sha256:
 cfeaa8e8fb4a26f1348f5476a759b39bfdb41f52076d694ef181221f7b0865fd 5004 glib2.0_2.84.4-3~deb13u4.dsc
 80ab88da1cbc594d3dbcf1ace06d25d86651b20378d11a91d27aae6ae39ca2ea 171232 glib2.0_2.84.4-3~deb13u4.debian.tar.xz
 3d4def1c47c094ffc8d18a0078dfb9f7680bfd6c774327e5f0db2e591aab0935 7787 glib2.0_2.84.4-3~deb13u4_source.buildinfo
Files:
 b55130ddd3fe6b4b8c6a78a2beb1a6a0 5004 libs optional glib2.0_2.84.4-3~deb13u4.dsc
 879462884894f8a64fe39abc6de9c6ee 171232 libs optional glib2.0_2.84.4-3~deb13u4.debian.tar.xz
 718e88b1b6c4a53533a31d3412b2b478 7787 libs optional glib2.0_2.84.4-3~deb13u4_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEegc60a5pT6Jb/2LlI1wJnT6zMHYFAmp1tr4ACgkQI1wJnT6z
MHbCMg//dtl4bCsh/sGRsjzua5RameeFRd4NTHki7gquKabC35LV+++eSp/MU//w
XxmIQJ0t6ke2f/PEkDXfbx4hpKBeqlqIDF2Dcpi1pQZeFHIUZFIsG1zHinWc7n6Y
jlnH+hhydokNqEde7MNj9v9GZFCVyztQD3+XESKBVZmILDuMgwmazfyZskxVgZIb
az2rjrCrInxZqhud5KTyKOewi36HLBaIHQYhRltCcbE/WrbzlW2Hw8PoixO0hW+7
EtuM9B6pzRDPPiT9zJrDCYCgNyL9/sbZCE7IyZ6kUBeXrb/f42s0KdGBjnO16Bcq
voqEeVFDtXmncqUZOny+pmiZg5QP5tjfJDxF5v2JdaN1CkDlj647eHLQMj+XpnbY
6DOxFXsaCfSC5wV3e9N9G03nsZ66hUu7G/rJFVWNyKKJ5INuSgOYIhxXQI5B+E11
GVqYmTA3sYJzN2lXII6x1jWBi/H+WxLxGlRK6BlPnDf2hh79ssB0d/8nejVWEaw5
td1IzEdT5fX/5r9NDRrBySriLv0OkxfA6c8mFl2wQ19xkYblvArLUX/j0Of7yqOI
Vm7UpBbIdIkG3KQ2sYz/RywNEAVfZFW1U6wkQEu939agtzvO5XQxpswST6EJul0w
xLEvRlutPYoNQc/Ry5NLvfdEEeC+cLExrxOHhQTOhzgxtQaTPHU=
=Y11X
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-gnome-maintainers/attachments/20260807/ad813b4a/attachment.sig>


More information about the pkg-gnome-maintainers mailing list