Source: bison Version: 2:3.8.2+dfsg-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for bison. CVE-2026-56389[0]: | GNU Bison allows for an execution of an arbitrary program during | HTML report generation due to improper handling of grammar-defined | configuration variables. A grammar file can override the executable | used for the XML‑to‑HTML transformation step via %define | tool.xsltproc, which is accepted without restriction and passed | directly to execvp(). When running bison --html on a attacker- | provided grammar, this behavior allows execution of an arbitrary | program with the privileges of the Bison process. Maintainers of | this project were notified about this vulnerability, and fixed the | issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, | they did not provide vulnerable version range. Version 3.8.2 was | tested and confirmed as vulnerable, other versions were not tested | but might also be vulnerable. CVE-2026-56390[1]: | GNU Bison improperly handles grammar‑defined output paths. Grammar | directives such as %output and %header allow specifying file paths, | which are accepted without restriction and override caller‑supplied | output options. When processing attacker-supplied grammar, this | behavior allows directing generated files to arbitrary writable | locations on the filesystem, potentially overwriting existing files | accessible to the Bison process. Maintainers of this project were | notified about this vulnerability, and fixed the issue in | commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did | not provide vulnerable version range. Version 3.8.2 was tested and | confirmed as vulnerable, other versions were not tested but might | also be vulnerable. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-56389 https://www.cve.org/CVERecord?id=CVE-2026-56389 [1] https://security-tracker.debian.org/tracker/CVE-2026-56390 https://www.cve.org/CVERecord?id=CVE-2026-56390 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

