[Pkg-utopia-maintainers] Bug#1144106: ostree: GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems
Simon McVittie
smcv at debian.org
Tue Aug 11 10:12:20 BST 2026
Package: libostree-1-1
Severity: important
Tags: security upstream help
X-Debbugs-Cc: Debian Security Team <team at security.debian.org>
Control: fixed -1 2026.3-1
https://github.com/ostreedev/ostree/security/advisories/GHSA-xppc-j946-vcj7
A vulnerability in libostree allows the operator of a malicious or
compromised OSTree repository to trigger a heap buffer overflow on
32-bit systems. All versions ever shipped by Debian appear to be
affected. There is currently no known CVE ID.
A mitigation is that only 32-bit architectures are affected.
I would very much appreciate it if someone else could take
responsibility for identifying the specific fixes and preparing a
backport to Debian 13.
Thanks,
smcv
More information about the Pkg-utopia-maintainers
mailing list