Your message dated Sat, 01 Aug 2026 12:49:09 +0000
with message-id <[email protected]>
and subject line Bug#1143053: fixed in open-isns 0.103-2
has caused the Debian Bug report #1143053,
regarding open-isns: CVE-2026-55995
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1143053: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1143053
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: open-isns
Version: 0.101-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for open-isns.

CVE-2026-55995[0]:
| A Double Free vulnerability in open-iscsi allows
| an unauthenticated MITM attacker to cause DoS.       This issue
| affects open-iscsi: from ? through
| 56718d4e9d1a4f51c30697b5c0534144bb41c9bb.

(note this is is really in open-isns, not open-iscsi source as in the
oficial CVE descirption, they reference to the [1] commit as fix).


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-55995
    https://www.cve.org/CVERecord?id=CVE-2026-55995
[1] 
https://github.com/open-iscsi/open-isns/commit/56718d4e9d1a4f51c30697b5c0534144bb41c9bb

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: open-isns
Source-Version: 0.103-2
Done: Chris Hofstaedtler <[email protected]>

We believe that the bug you reported is fixed in the latest version of
open-isns, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Chris Hofstaedtler <[email protected]> (supplier of updated open-isns package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 01 Aug 2026 14:32:19 +0200
Source: open-isns
Architecture: source
Version: 0.103-2
Distribution: unstable
Urgency: medium
Maintainer: Debian iSCSI Maintainers <[email protected]>
Changed-By: Chris Hofstaedtler <[email protected]>
Closes: 1143053
Changes:
 open-isns (0.103-2) unstable; urgency=medium
 .
   * Team upload.
   * Pick upstream fix for CVE-2026-55995 (Closes: #1143053)
   * d/changelog: remove incorrect CVE fix mention in 0.103-1
   * d/control: remove Testsuite: autopkgtest to fix lintian warning
     unnecessary-testsuite-autopkgtest-field
   * Remove Christian Seiler from Uploaders.
     Thank you for your past contributions.
Checksums-Sha1:
 aa9292d7ea016444bb7bb98ef37985f9647c29d8 2341 open-isns_0.103-2.dsc
 42eeca3023a4fd9c78ac63a0df2fae70da11cb33 19136 open-isns_0.103-2.debian.tar.xz
 47b87b4b5610b2532e095a837cc45560375555b0 9184 open-isns_0.103-2_arm64.buildinfo
Checksums-Sha256:
 3bcedfc84ab333e241f8c1dd4df888db6c811ffabdc97fe038bd03d752f08f3d 2341 
open-isns_0.103-2.dsc
 9a30ed7a6cefa1866f33f88ce67f6ee88f2e1bc59d220dc8cecb2d2f6feaf896 19136 
open-isns_0.103-2.debian.tar.xz
 619d77e6a1d2f0ca6b4c889d83a9125f7293a8528f02bad2988892527c9081bd 9184 
open-isns_0.103-2_arm64.buildinfo
Files:
 626b2145e41d74c03c37d28093d9b56f 2341 net optional open-isns_0.103-2.dsc
 e28be8992ea9c59a910f988fe122c6e7 19136 net optional 
open-isns_0.103-2.debian.tar.xz
 ab6a0c86c89ffc33904360812e23bab7 9184 net optional 
open-isns_0.103-2_arm64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfRrP+tnggGycTNOSXBPW25MFLgMFAmpt6XYACgkQXBPW25MF
LgN6eA/+KT0FBHdiPWBMUILJUkuU5rO84vGY0Ab/koARsgSmEeW6QNWCsjCnJF2d
iusYODCwLscWDs1yLESU0yDGbKc2ye/HSZdOkiaFnReCSkv3prDPjmPs2dexWYkb
gYnJ3Gw+WLwN0prKKWm7lPzqeZAN1PkSf3QRwBXgzpKKtQbsiCmp0xQ518UUA+Sn
5TeLcFALiQzxTmjlR1oJ0qTsVxCMk1qk5y4KwOFENy9v4mN9heEn0Fk4jpBIG4mu
qUNocPcqCY82HuuOKs2908R+ZoGJhVtb0B0Ph86TlRnT0iZeJWeP62gWRDDA6Ahe
Rl42D1SnWGnlx5Wb+lF4sm9W06gOzS3UlFT+jmUO7ffLE/M8cy7d5JmhSvfgUwhF
aMCGuxUX9H0vbdPslaEmvinrb6xar1rc9Z6ajTHsfCPDoAOv59YI2uFBRsoQo7R+
zjHSGPJG42mMIF/OU1jegfFDhfxx9yg2TdnmuB482jhQSXUjCaua29WRqR1S90u1
/w4z6kq1QBdAOQiXwS85xYvQVCSDa7xYlH3HQhCgK0ywSLXUfo3GlmysLKXbmjEb
YPnaMLz5bleG4y10kBDGCODgLgr1VjHlyb3eb5RvfiMVvpRGX6g76wVlSqQvES5q
HzVrvB9nO7DOMkJROq+W4SAD9O4uKPQIOYIqxxLeE1Qf7PjzrYk=
=+0Dy
-----END PGP SIGNATURE-----

Attachment: pgp65t0rTgXWY.pgp
Description: PGP signature


--- End Message ---

Reply via email to