Your message dated Tue, 15 Sep 2026 15:04:24 +0000
with message-id <[email protected]>
and subject line Bug#1147615: fixed in urwid 4.1.3-1
has caused the Debian Bug report #1147615,
regarding urwid: CVE-2026-9323
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1147615: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1147615
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: urwid
X-Debbugs-CC: [email protected]
Severity: important
Tags: security
Hi,
The following vulnerability was published for urwid.
CVE-2026-9323[0]:
| The urwid web display backend (urwid/display/web.py) generates web
| session identifiers (urwid_id) in Screen.start() by concatenating
| two random.randrange(10**9) calls that use Python's Mersenne Twister
| PRNG, which is not cryptographically secure. Each call consumes
| approximately 30 bits of PRNG state, and the Mersenne Twister
| internal state is approximately 19,937 bits, so an attacker who
| observes approximately 334 session IDs (for example via the X-Urwid-
| ID HTTP response header) can fully reconstruct the internal state
| and predict all past and future session IDs (Path B). The same
| identifier is also used as the filename of a FIFO created in the
| world-listable /tmp directory (for example
| /tmp/urwid375487765176907690.in), so any local user on the host can
| list /tmp to enumerate active session tokens directly (Path A). With
| a valid session ID, an attacker can read the victim's terminal
| screen via the polling endpoint, inject keystrokes into the victim's
| session (yielding OS-level code execution with the session owner's
| privileges if the session runs a shell), and inject exit sequences
| or flood the FIFO to terminate or crash the session. A prior Bandit
| S311 warning on this usage was suppressed with # noqa: S311 rather
| than fixed
https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv
https://github.com/urwid/urwid/pull/1128
Fixed by:
https://github.com/urwid/urwid/commit/24acd12f0d0598036d0d577f2ee63e4a27b4a3d9
(4.0.2)
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-9323
https://www.cve.org/CVERecord?id=CVE-2026-9323
Please adjust the affected versions in the BTS as needed.
--- End Message ---
--- Begin Message ---
Source: urwid
Source-Version: 4.1.3-1
Done: Boyuan Yang <[email protected]>
We believe that the bug you reported is fixed in the latest version of
urwid, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Boyuan Yang <[email protected]> (supplier of updated urwid package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Tue, 15 Sep 2026 10:39:25 -0400
Source: urwid
Architecture: source
Version: 4.1.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Python Team <[email protected]>
Changed-By: Boyuan Yang <[email protected]>
Closes: 1147615
Changes:
urwid (4.1.3-1) unstable; urgency=medium
.
* Team upload.
* New upstream release.
+ Fix CVE-2026-9323: (Closes: #1147615)
* debian/control: Bump Standards-Version to 4.7.4.
* debian/control: Bump debhelper compat to v14.
* debian/control: Add python3-gi, python3-tornado, python3-trio and
python3-zmq as <!nodoc> build-dependencies.
* Make the nodoc build profile actually skip the documentation:
+ debian/control: Mark python-urwid-doc with Build-Profiles: <!nodoc>
and restrict python3-sphinx and dh-sequence-sphinxdoc to <!nodoc>.
+ debian/rules: Only run Sphinx when the nodoc profile is not active.
* debian/python-urwid-doc.doc-base: Register the HTML documentation with
doc-base.
* debian/rules: Stop deleting tests/test_vterm.py. The vterm tests were
disabled in 1.2.1-2 because they raced against a real PTY on slow
architectures (#743685); upstream rewrote them to use an in-memory fake
PTY with all system calls mocked, so they are deterministic now.
* debian/control: Switch Testsuite to autopkgtest-pkg-pybuild so that the
full upstream test suite runs against the installed package.
Checksums-Sha1:
81c603a608fd3faf23fc2150176d7de5a6890c77 3189 urwid_4.1.3-1.dsc
82711859fc73c94978af2e49806b266f276811a0 901922 urwid_4.1.3.orig.tar.gz
fc9b1e88c10e64680b10ab70bcc8566951cd694b 6924 urwid_4.1.3-1.debian.tar.xz
327384994ee986e76463610511fda435f629cba9 9116 urwid_4.1.3-1_amd64.buildinfo
Checksums-Sha256:
fd6ad263122023eb5e95f379d8864f35d9184865e0e47f3a609ebefadf289778 3189
urwid_4.1.3-1.dsc
d61054ad300f33b959258d6761815b45debb3a67298539b3e1f38f933e70a7bf 901922
urwid_4.1.3.orig.tar.gz
573d2317b54d74b4e62e0f3b7128bdfc7931598b0ea08b4dad22a0cf461e51cb 6924
urwid_4.1.3-1.debian.tar.xz
0d78e95f8b209479bd8fa6ab6757c7d4aac087409d0429318825211978c53353 9116
urwid_4.1.3-1_amd64.buildinfo
Files:
15b6d8b60f6214dde9e221e8adebdfb7 3189 python optional urwid_4.1.3-1.dsc
6e3586b783fafc7b9918222c50c49ef5 901922 python optional urwid_4.1.3.orig.tar.gz
f35fbd4fcdc6ae82bcbdab5eba39c33a 6924 python optional
urwid_4.1.3-1.debian.tar.xz
3af203793ae0446c656e4e7ed1a07a3e 9116 python optional
urwid_4.1.3-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEfncpR22H1vEdkazLwpPntGGCWs4FAmqpWT0ACgkQwpPntGGC
Ws4ZgxAAlvEg/BoePzCRMIf2KlatsLnHCtcnsI0REmHjN8kDxmrDeDFUUEah6c6s
xjVM3Hpm1okaIJx9Q5C36MQuPO6/5+0OOPT+OP3RjtoOUIFudhjfAUTHeh94KVbT
I54eN2Fq0fthDAQcnUNNn+Avmy3RZlhgnmwqxzw5NfxLFtr2JZUBkpvv78ybCVv3
UQQwrE42OowUO5CR7jfXedzbqotjOOxRqHacrB9URNDt6pF8YjsDBRqpazSsd1wP
2qpVCGsNpodICU1erK/RghkiTafgufp1MDvHjuKeMJJx3rdxf7lAPP27h4kDA4YK
16UGKmSfoR/YkrgJV2Pshkngy+Z50g3nOtYpKk/XrFkYGWcvyndyd6JOuSEXoYYS
gl6OkateeF/VCDFbkkkJd2w5xSL/j1SDWMjtRnYMJh28ruzsXGPEJ/+VeMYUwXdH
wz4SWKvn+WvK9/X8mk+4j84OSFV0AW+5YZS8IoOJj1LlQAD2zKGEQuS97SWbCT+W
B/mtrbKnOVWArzZ8BgM1j9Kv8C+nqYs2vPhiUq4hmOPDUrqdmGFgSoaKmHK7lcIV
UhkUje12u0PhUBrwwhIKR3eAllen0ZBpKTmAOA5iDvGY/d9bQYgLH/5gMsq2UpZ/
E1a0c9SOEafcVD927URdl8KeuYCtIucj6S/gh0qj7of5thiGDhA=
=xjDf
-----END PGP SIGNATURE-----
pgpwVLCnYvPq5.pgp
Description: PGP signature
--- End Message ---