jackson-core_2.14.1-2_source.changes ACCEPTED into unstable
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Wed Apr 15 22:05:52 BST 2026
Thank you for your contribution to Debian.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Wed, 15 Apr 2026 13:27:34 +0200
Source: jackson-core
Architecture: source
Version: 2.14.1-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers at lists.alioth.debian.org>
Changed-By: Markus Koschany <apo at debian.org>
Closes: 1108367
Changes:
jackson-core (2.14.1-2) unstable; urgency=medium
.
* Team upload.
.
[ Markus Koschany and Emmanuel Arias ]
* CVE-2025-52999:
A limit was added to avoid a StackoverflowError if the parsed JSON is very
deeply nested. The StackoverflowError issue happens in jackson-databind but
this change in jackson-core stops it from happening unless you increase the
StreamReadConstraints.maxNestingDepth() to a high number. (Closes: #1108367).
* Declare compliance with Debian Policy 4.7.4.
Checksums-Sha1:
e137e5ec89028f143a7c5376671cead9e44525ba 2375 jackson-core_2.14.1-2.dsc
517a2371a79892a77d9eec98b597368b5b9a2670 738136 jackson-core_2.14.1.orig.tar.xz
55a58c86b87389ef26542b487144ed4843be91e0 48968 jackson-core_2.14.1-2.debian.tar.xz
04e25c090af03ccfaebbe024d019be595043f419 15811 jackson-core_2.14.1-2_amd64.buildinfo
Checksums-Sha256:
883f858940dd56aa6e2a4683bc1ffc02cbe354a01f6f3bf6a6116f0b9b67a6fa 2375 jackson-core_2.14.1-2.dsc
d9eb6aa1898c4d5a582c52e69da249efae25e4d2c809c57dc6b6ee01c4b0fb3b 738136 jackson-core_2.14.1.orig.tar.xz
0c6e23f04491029793e574e543b476d7f2ee5143a1d6f852e96efa9c67364040 48968 jackson-core_2.14.1-2.debian.tar.xz
29b38f85a2799ca7cb6829d5cd3d214d374a4ce29b94c277d519eae6ca99c35b 15811 jackson-core_2.14.1-2_amd64.buildinfo
Files:
c0622dd9b76c815a45d3027dcac74174 2375 java optional jackson-core_2.14.1-2.dsc
38458c564bc7bed7e92d2cc2b46b1764 738136 java optional jackson-core_2.14.1.orig.tar.xz
9c40043876f1cc0fc9496e58a4dd9349 48968 java optional jackson-core_2.14.1-2.debian.tar.xz
b421239da9b9216c15561276c9a4b4c2 15811 java optional jackson-core_2.14.1-2_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmnf+OxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD
RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp
YW4ub3JnAAoJENmtFLlRO1HkKTYP+gP3IQBn3lC4eGe5TstH4Wg59alOf5ieoqTp
Q1RsJ9JvZ6EFqEmTlvRCRKRN1NLYZwQc5mHFLblFVUIU1xAIXiI6PA3vD73ojJbX
/6W3jMn8K+0cY1HFwgOw34ewQjDJ1Do47L6ij2GxJmTc1/rs3qQskG+ggxWZslkE
cZVRABPiiwoNV7wjQM627FmpNSHP464PE+v3juHlUQYchPihtijBE6IYX5rPRm+z
hyjhnHe7iqokiTKcCzHZMMcXhjmzr0tt9sSyyy/CRxMF54g36Czd+DnD8F9b76ZJ
Hf/lQVRcKfWqpBx94M+juX8/SxAaSQBEm2HnAecpaU9m5nY6HSqRk3XvCdMf/Mfu
URO9nC+6Cduycenjs/Vm8uRnAS5Qixw8V6E1XYA4z4bIzGYHiVjNzlN+3ROe/C/C
qZSAugzqgGR/eG6Ex8c2Rjs9e/SiH+nuemXQXcsYsD0ICekeJAGmnyHp/RoeBwiG
HX4ZM2fJIog+JT7rWXPTQvZmFyeFizZR23Rfoq3fiLpRpxBe+z6oVHN1MWeSGv02
D0Vag8oN/i76oaJalTsiIi9mMN1fMGT5RNTlWAaxMXq5uR6vrSi7rf5GKY2DRTst
nJk9gWzqTZGsshmDawP80poAA/otNmhWPanxDWENlyxHQVQcDUR/QYKSIjjian4A
EtTwIr3X
=8z+I
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-java-maintainers/attachments/20260415/e84f326d/attachment.sig>
More information about the pkg-java-maintainers
mailing list