Your message dated Mon, 03 Aug 2026 21:49:01 +0000
with message-id <[email protected]>
and subject line Bug#1134644: fixed in golang-github-gomarkdown-markdown 
0.0~git20260725.8435af3-1
has caused the Debian Bug report #1134644,
regarding golang-github-gomarkdown-markdown: CVE-2026-40890
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1134644: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1134644
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: golang-github-gomarkdown-markdown
X-Debbugs-CC: [email protected]
Severity: important
Tags: security

Hi,

The following vulnerability was published for golang-github-gomarkdown-markdown.

CVE-2026-40890[0]:
| The package `github.com/gomarkdown/markdown` is a Go library for
| parsing Markdown text and rendering as HTML. Processing a malformed
| input containing a < character that is not followed by a > character
| anywhere in the remaining text with a SmartypantsRenderer will lead
| to Out of Bounds read or a panic. This vulnerability is fixed with
| commit 759bbc3e32073c3bc4e25969c132fc520eda2778.

https://github.com/gomarkdown/markdown/security/advisories/GHSA-77fj-vx54-gvh7
https://github.com/gomarkdown/markdown/commit/759bbc3e32073c3bc4e25969c132fc520eda2778
 

If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-40890
    https://www.cve.org/CVERecord?id=CVE-2026-40890

Please adjust the affected versions in the BTS as needed.

--- End Message ---
--- Begin Message ---
Source: golang-github-gomarkdown-markdown
Source-Version: 0.0~git20260725.8435af3-1
Done: Simon Josefsson <[email protected]>

We believe that the bug you reported is fixed in the latest version of
golang-github-gomarkdown-markdown, which is due to be installed in the Debian 
FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Josefsson <[email protected]> (supplier of updated 
golang-github-gomarkdown-markdown package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 03 Aug 2026 23:22:03 +0200
Source: golang-github-gomarkdown-markdown
Architecture: source
Version: 0.0~git20260725.8435af3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <[email protected]>
Changed-By: Simon Josefsson <[email protected]>
Closes: 1085377 1134644
Changes:
 golang-github-gomarkdown-markdown (0.0~git20260725.8435af3-1) unstable; 
urgency=medium
 .
   * Team upload
   * New upstream
     - CVE-2024-44337 GHSA-xhr3-wf7j-h255 (Closes: #1085377)
     - CVE-2026-40890 GHSA-77fj-vx54-gvh7 (Closes: #1134644)
     - GHSA-gc99-qr5c-98ff
   * Drop redundant `Priority: optional`
   * Drop redundant `Rules-Requires-Root: no`
   * Bump Debian Policy version to 4.7.4
   * Use watch v5
   * Drop d/.gitignore
   * Use gbp sign-tags
   * Bump debian/* copyright years
   * Use compat 14
Checksums-Sha1:
 db458818fdc1fdd5e6f8d57dd87f6003890fab95 2744 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.dsc
 71526960e78a9ec57ea1215b62150ea2f96501f6 108700 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3.orig.tar.xz
 8c1ba7db7956ce9d4b75eaa61e33064bccbe7b77 3016 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.debian.tar.xz
 d20a1d4057393bdb99b1794f7907ca1ec3a95579 307160 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.git.tar.xz
 edaf01fa2ea39b3742d8213ea37786f368bf1f20 17728 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1_source.buildinfo
Checksums-Sha256:
 ba3d33f5c7c12f73f052d332188a12ad2604160138d2f4cb939da278046a2e35 2744 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.dsc
 8cec0c2d5b15b04d93ee366feb759344696913e37fef3490c38788bf228d9b4d 108700 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3.orig.tar.xz
 9347bab256b53238393904d09c67501b0ff7b5c9fe231af78b01b67f91db1f29 3016 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.debian.tar.xz
 9e48d9a42ade3a1c0a57688cd59222bf690dbca3ae644b3d64def70b57795eca 307160 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.git.tar.xz
 9903f4e9e42c26a05521d866c9f6b11ac8281012eda226fed9bfd10f7a66dd0b 17728 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1_source.buildinfo
Files:
 ef03e6171489ec1b07e7f3fcc849391a 2744 golang optional 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.dsc
 1e17843c6a32c64a6d09e1d311c9d8ad 108700 golang optional 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3.orig.tar.xz
 4e110ebb835c6c8b12e45296f4978e01 3016 golang optional 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.debian.tar.xz
 4f807f93609e3040fb42a37d425e0f86 307160 golang None 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1.git.tar.xz
 6bb339fb82b3f4c524fa52ca5b4396d0 17728 golang optional 
golang-github-gomarkdown-markdown_0.0~git20260725.8435af3-1_source.buildinfo
Git-Tag-Info: tag=6c701e6e11538d4080c1f115dab4abd2810b7a1b 
fp=a3cc9c870b9d310abad4cf2f51722b08fe4745a2
Git-Tag-Tagger: Simon Josefsson <[email protected]>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpxCGwACgkQYG0ITkaD
wHkpGBAApWhi9t70gVh1AqUIWCjMINvtPEBADsGIEptDuW1IzyKTiHUvos6mRNY4
sg5dx5DmanSTHdUikbCvVT4paWgNKITmhuUdb7bULDqueYw4JgTwoT3KeiPWFKJs
Q0t6cw6dduyt6CG9pY687qsexnTe4+ZLGu6lOLW96CZ2Rnx0vShLIid4zCxpmzz0
cpqENejz/n+c/S1lWZ9aU5PF+AQKWvxBC36IGn6nBWKp4nbG8Spq/WxW0i6FN4c4
vodf66fK/uO/C6sbiRneHTTWXT2FpUcIGDHwA4y1cHOFZ/38rLNPYt9zt0mgzH05
t5oKwZrxJI/Wi4Iqs4nLvcInBCLB44Z1ZzngZpnW7BP+NVZnAdJzg6BWNN8j1db7
P9Gsay//JbW4LEO0VfVAharYlyZCi/hCsC5enjjM+mU7xYU6DrWHLXRlhnoT+SSI
dQW+5LNvWi1z3Jhac/nlrTiL198XUDfIpiLMJbIRolsVoZm8GkumfoD142ppLyn0
NPjgQ6wC9dPJc9Bj7T8IM3i+6khHuroDE8H3Z89uacW7L0oRKfrfYTPMhaJva2vp
DhhOXvsfaJmhoDedqgSTH/okOmz24i2xmHcMiRusqONHSA2sR/MAv10dSeM6bQAH
bTxloiiY/HtYWlI0oM5IE3hG5CDpfFVK4loieVPdLfu3FI7QgCU=
=dLpE
-----END PGP SIGNATURE-----

Attachment: pgpSoUB8gr5Hd.pgp
Description: PGP signature


--- End Message ---

Reply via email to