Your message dated Tue, 25 Aug 2026 19:14:57 -0700
with message-id 
<CAOMoQbSHyAnLMTqd4=yygqp+l3v596woh8kav48eozcqxdc...@mail.gmail.com>
and subject line pgbouncer: CVE-2026-6664 CVE-2026-6665 CVE-2026-6666 
CVE-2026-6667
has caused the Debian Bug report #1136075,
regarding pgbouncer: CVE-2026-6664 CVE-2026-6665 CVE-2026-6666 CVE-2026-6667
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1136075: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1136075
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: pgbouncer
Version: 1.25.1-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for pgbouncer.

CVE-2026-6664[0]:
| An integer overflow in network packet parsing code in PgBouncer
| before 1.25.2 bypasses a boundary check and can lead to a crash. An
| unauthenticated remote attacker can crash PgBouncer with a malformed
| SCRAM authentication packet.


CVE-2026-6665[1]:
| The SCRAM code in PgBouncer before 1.25.2 did not check the return
| value of strlcat() correctly when building the contents of the SCRAM
| client-final-message. A malicious backend that sends a SCRAM server-
| final-message with a long nonce can trigger a stack overflow.


CVE-2026-6666[2]:
| A possible null pointer reference in PgBouncer before 1.25.2 could
| lead to a crash, if a server sends an error response without
| SQLSTATE field.


CVE-2026-6667[3]:
| PgBouncer before 1.25.2 did not perform an appropriate authorization
| check for the KILL_CLIENT admin command. All users with access to
| the administration console (which itself requires authorization)
| could run this command. It would have been correct to allow only
| users listed in the admin_users parameter.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-6664
    https://www.cve.org/CVERecord?id=CVE-2026-6664
[1] https://security-tracker.debian.org/tracker/CVE-2026-6665
    https://www.cve.org/CVERecord?id=CVE-2026-6665
[2] https://security-tracker.debian.org/tracker/CVE-2026-6666
    https://www.cve.org/CVERecord?id=CVE-2026-6666
[3] https://security-tracker.debian.org/tracker/CVE-2026-6667
    https://www.cve.org/CVERecord?id=CVE-2026-6667

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Version: 1.25.2-1

PgBouncer 1.25.2 was packaged and uploaded back in May 2026 [0].

[0]: 
https://salsa.debian.org/postgresql/pgbouncer/-/commit/a7cae0c2cf6a305129056d61ba01faabf837d61d

--- End Message ---

Reply via email to