Your message dated Mon, 31 Aug 2026 13:47:09 +0000
with message-id <[email protected]>
and subject line Bug#1144975: fixed in cockpit 337-1+deb13u2
has caused the Debian Bug report #1144975,
regarding cockpit: CVE-2026-76235
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1144975: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144975
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: cockpit
Version: 365-1
Severity: important
Tags: security upstream
Forwarded: https://github.com/cockpit-project/cockpit/pull/23633
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for cockpit.
CVE-2026-76235[0]:
| A memory leak flaw was found in cockpit-ws. The login page handler
| leaks a heap allocation on every unauthenticated request that
| carries a CockpitLang cookie, allowing a remote unauthenticated
| attacker to exhaust memory on the host and cause a denial of
| service.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-76235
https://www.cve.org/CVERecord?id=CVE-2026-76235
[1] https://github.com/cockpit-project/cockpit/pull/23633
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: cockpit
Source-Version: 337-1+deb13u2
Done: Martin Pitt <[email protected]>
We believe that the bug you reported is fixed in the latest version of
cockpit, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Martin Pitt <[email protected]> (supplier of updated cockpit package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 25 Aug 2026 08:35:13 +0200
Source: cockpit
Architecture: source
Version: 337-1+deb13u2
Distribution: trixie-security
Urgency: medium
Maintainer: Utopia Maintenance Team
<[email protected]>
Changed-By: Martin Pitt <[email protected]>
Closes: 1144975
Changes:
cockpit (337-1+deb13u2) trixie-security; urgency=medium
.
* ws: Free "language" string also when it comes from the cookie.
Fixes remote unauthenticated DoS and huge memory usage (throttled at 75%
and capped at 90% via systemd slice resource control).
[CVE-2026-76235] (Closes: #1144975)
* pkg/systemd: robustify argument quoting. Fixes arbitrary command
execution via crafted links to the system logs user interface.
Patch backported from upstream commit e3a47d70f99a0d, and hand-applied in
debian/rules to the built bundle, as this branch does not yet rebuild
the bundles during package build. [CVE-2026-4802]
has no effect; instead apply the equivalent change to the shipped
dist/systemd/logs.js.gz via sed in debian/rules.
Checksums-Sha1:
5101f7ee3eacb6266915e79888b2ca5abd7676de 3007 cockpit_337-1+deb13u2.dsc
9a45726c9e5e5078e2d69ec9eac5676171c972bd 14759784 cockpit_337.orig.tar.xz
17a7844eb71db11fd8d667231cb43ca726614796 25428
cockpit_337-1+deb13u2.debian.tar.xz
88ae2f9ad5bb5fc65309dcef077051b403a3e146 11176
cockpit_337-1+deb13u2_source.buildinfo
Checksums-Sha256:
9ba12b9ebdadbcb34d78fd039997e0ef936e98ded322ebf9862fb5224b124def 3007
cockpit_337-1+deb13u2.dsc
df51ef5920fae69e1b435f657376aa93772c0c1720b954a3bac10ebba26bfedf 14759784
cockpit_337.orig.tar.xz
c5fc9d0f56a16d5af3fb6ecd556d174664fbd7f5abe26d470bb4d7f147f0f55f 25428
cockpit_337-1+deb13u2.debian.tar.xz
a98671103fe4b5ce1b71a1ca0b267d4dc19888cd2a1b6425af81abd2a0c9bc6c 11176
cockpit_337-1+deb13u2_source.buildinfo
Files:
5f68ce133c1b614da5a41b48fca7f24d 3007 admin optional cockpit_337-1+deb13u2.dsc
9c03bb1048d7bfa99bc5e3ca953457e8 14759784 admin optional
cockpit_337.orig.tar.xz
3d8b239060116ad0609b45379478864f 25428 admin optional
cockpit_337-1+deb13u2.debian.tar.xz
b0b9c2767f0c29ca0e8cdda94441d80b 11176 admin optional
cockpit_337-1+deb13u2_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEbEuHi35jHxYFV8PN7nvd5LhrVxMFAmqP2QAACgkQ7nvd5Lhr
VxPCmxAAl8vlCHqXqwZPwTa9EZ4ekGs5PPiQiI9m01tjOtagq19AW7Gvi6kV2ZQn
G8zMyp7jO4IUjYkxcy06m2Ji2COjOzSZmTtn5Sv/gi3swkbT5sC9hfxSE2o4bT6o
VMs5ISyEpiuZliooArktWHq15GumQXvE6kM90yDe1R0XcxmCdgr9PQ6ppH89Pd+F
MdE8CMw3Ytz8vNiRCAAx1Mx+7zzrevGwa2uwhxsKlMe2QKDYC8qJyJHCpsVAPZEX
QVb+DUKrujo4z2QxIZNKnBjaoTOd5GP3XL+lk2HcmB0UwW1J5FHekoxxQwFxgTsR
E+3EuLQD5ynjMQr2ksZD7n7tPPddltCDDl+TsaKFVjTlOLXGSMhLv9PuwEKPIrS+
Edkluv+C19cpRSG5M0t9ZIFe2bAljufhchvDZS+cgMgn/EK9F05oTY3LgB3bHoLW
U2GWieiqgViUNozxCRhcCJ7h02rV3Fa9CYagQdb2KVFBcYkNc9th3E7QgnS9hILE
kXuIeWU905NECwZKIwNHPbEfh/qWgpd4MxFxFPCepQdFbQCJbNEX7O0d1TSaR0X/
ulcuH7RBwWuOBjo9oB0uCVB76Frgj7M2pnrjmQqL1SyDwGo2iR+9YUQ8XUvth0wL
vBjAV7BIqgGfRocX6Q7zzKqbuxuuDWM1UNYcdED6Tx7CWKCNr+I=
=vBwn
-----END PGP SIGNATURE-----
pgpf5jpG0CH26.pgp
Description: PGP signature
--- End Message ---