Your message dated Tue, 28 Jul 2026 16:33:58 +0000
with message-id <[email protected]>
and subject line Bug#1142456: fixed in golang-oras-oras-go 2.6.2-1
has caused the Debian Bug report #1142456,
regarding golang-oras-oras-go: CVE-2026-48978 CVE-2026-50151 CVE-2026-50162 
CVE-2026-50163
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142456: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142456
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: golang-oras-oras-go
Version: 2.6.0-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for golang-oras-oras-go.

CVE-2026-48978[0]:
| oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1,
| auth.Client follows the realm URL from a registry's WWW-
| Authenticate: Bearer challenge without validating the scheme or
| host, allowing a malicious or compromised registry to cause SSRF to
| internal networks such as http://169.254.169.254/, http://10.0.0.x/,
| and http://127.0.0.1/, or to downgrade a registry contacted over
| https:// to an http:// token endpoint in
| registry/remote/auth/client.go through Client.Do(),
| Client.fetchBearerToken(), fetchDistributionToken, and
| fetchOAuth2Token. This issue is fixed in version 2.6.1.


CVE-2026-50151[1]:
| oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1,
| registry/remote/repository.go in
| blobStore.completePushAfterInitialPost follows a registry-controlled
| Location header during monolithic blob upload and reuses the
| Authorization header from the initial POST request for the
| subsequent PUT request, allowing a malicious registry to return a
| cross-host Location and receive the caller's credentials at an
| attacker-controlled endpoint. This issue is fixed in version 2.6.1.


CVE-2026-50162[2]:
| oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1,
| resolveWritePath() in content/file/file.go uses a lexical
| filepath.Rel check for workingDir and does not account for symlink
| traversal, so when AllowPathTraversalOnWrite=false an attacker-
| controlled blob title through ocispec.AnnotationTitle such as
| out/pwn.txt can follow a workingDir symlink out -> /some/outside/dir
| and cause pushFile() to create /some/outside/dir/pwn.txt outside
| workingDir. This issue is fixed in version 2.6.1.


CVE-2026-50163[3]:
| oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2,
| ensureLinkPath in content/file/utils.go:262-275 validates a hardlink
| target relative to the extract base but returns the unresolved
| target, causing os.Link("victim.secret",
| "<extract_base>/payload.tar.gz/evil_cwd_link") to resolve
| header.Linkname against the process current working directory for a
| Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link
| and Linkname="victim.secret" with io.deis.oras.content.unpack:
| "true", which can expose or tamper with files such as .env,
| .git/config, .aws/credentials, and ~/.ssh/config. This issue is
| fixed in version 2.6.2.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-48978
    https://www.cve.org/CVERecord?id=CVE-2026-48978
[1] https://security-tracker.debian.org/tracker/CVE-2026-50151
    https://www.cve.org/CVERecord?id=CVE-2026-50151
[2] https://security-tracker.debian.org/tracker/CVE-2026-50162
    https://www.cve.org/CVERecord?id=CVE-2026-50162
[3] https://security-tracker.debian.org/tracker/CVE-2026-50163
    https://www.cve.org/CVERecord?id=CVE-2026-50163

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: golang-oras-oras-go
Source-Version: 2.6.2-1
Done: Simon Josefsson <[email protected]>

We believe that the bug you reported is fixed in the latest version of
golang-oras-oras-go, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Simon Josefsson <[email protected]> (supplier of updated golang-oras-oras-go 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 28 Jul 2026 17:56:57 +0200
Source: golang-oras-oras-go
Architecture: source
Version: 2.6.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Go Packaging Team <[email protected]>
Changed-By: Simon Josefsson <[email protected]>
Closes: 1142456
Changes:
 golang-oras-oras-go (2.6.2-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream (Closes: #1142456)
     - CVE-2026-48978
     - CVE-2026-50151
     - CVE-2026-50162
     - CVE-2026-50163
   * Update copyright years for recent contributors
   * Apply consistent formatting to packaging files
   * Drop redundant `Priority: optional`
   * Bump Debian Policy version to 4.7.4
   * Use dh-sequence-golang
   * Use watch v5 and pin to v2.*
   * Revert debcraft-garbled copyright line
   * Bump debian/* copyright years
   * Use gbp sign-tags and upstream-vcs-tag
   * Use compat 14
   * Breaks:golang-github-notaryproject-notation-go-dev <= 1.3.2-3
   * Trim execute_after commands (cannot reproduce need)
Checksums-Sha1:
 ebe7924dc95ee8e1bd694782f054d98f2a635859 2572 golang-oras-oras-go_2.6.2-1.dsc
 2a18468fc7210d27d7e75fce2c18e266f030434b 185892 
golang-oras-oras-go_2.6.2.orig.tar.xz
 7b9d9fd15a108c6e8bd39d9e1e2ee0fdcfae935a 2596 
golang-oras-oras-go_2.6.2-1.debian.tar.xz
 f48d8b07df185a9e29882419a7b9d55443ee7b57 610564 
golang-oras-oras-go_2.6.2-1.git.tar.xz
 62401ba1c7c7920be98fa5fe07a9ae93d81dcbb8 17594 
golang-oras-oras-go_2.6.2-1_source.buildinfo
Checksums-Sha256:
 bd2eb4bc8de880ee70c11050aebcea2f7853116e00459b8babdb96fcec1f87d9 2572 
golang-oras-oras-go_2.6.2-1.dsc
 fd74088f937844755911a6989b01a5bab8b8a07e0ad3bde83fff3deb9c5df669 185892 
golang-oras-oras-go_2.6.2.orig.tar.xz
 7a259aefaa2a58e95cf8d6062e91de446cbc37e0461b14fba9b5abaa581d3fc7 2596 
golang-oras-oras-go_2.6.2-1.debian.tar.xz
 2d230406df116fc729fd92691c54331ab2b4b106c39c91ee5786321e5a141b57 610564 
golang-oras-oras-go_2.6.2-1.git.tar.xz
 9f9de6b1c29ae129c1aa74bc8c0a2a0f0c563bc9bb4304a2e5d483111a7e37a9 17594 
golang-oras-oras-go_2.6.2-1_source.buildinfo
Files:
 8b8782e0c17cf189efd6ee0a7f1ed237 2572 golang optional 
golang-oras-oras-go_2.6.2-1.dsc
 3c84a04740fccc1fe0e1a960107039d6 185892 golang optional 
golang-oras-oras-go_2.6.2.orig.tar.xz
 00e11128fe4834d2191bab0c5b2146e1 2596 golang optional 
golang-oras-oras-go_2.6.2-1.debian.tar.xz
 81660f25973791eb2fd3a2cf100d7c3e 610564 golang None 
golang-oras-oras-go_2.6.2-1.git.tar.xz
 a98e07c11d9c1825f4f6768abc250d1f 17594 golang optional 
golang-oras-oras-go_2.6.2-1_source.buildinfo
Git-Tag-Info: tag=6b9f3c8605e43568235a782035d1f860519a7014 
fp=a3cc9c870b9d310abad4cf2f51722b08fe4745a2
Git-Tag-Tagger: Simon Josefsson <[email protected]>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEN02M5NuW6cvUwJcqYG0ITkaDwHkFAmpo1LUACgkQYG0ITkaD
wHk2rRAAuO+4JkFpuCblgbJ9J6STNsr5KlqQUMwv8btCJVVc9Zvz2VBlg4GEh5Dt
vIgZGbM/p4Op42TzFX4Xsy+JC0WMrehkC6iFhDGD7XiJZAfppyh+43YMkg2Tbqqu
dSoMc8uBXiGKfo/UVvZpU82XFgX7S/+EN47+A4EMUP7J0L9px8WahyhSvHsK/QFp
ahGyEl+nJFSPUhafuMWevEySdvQNx3RHaoesN2C8xhVzk+9kcq7UDucOwvcU3IvK
lzQBcvXkTHH23foxMHwfYH//ICjgu7hVT4f3NGozlXZYRZ8LlcP7UDv5Qy1plPM9
JqJabo5wMjKKNjOk9H/LYJUjYcFxMwGqKUDK7J8WVN4nD1x+eQdl9cfpIwh9eBTF
njTEENfLLbO/9gY3VeuapI9UvIUz/PhIqUadcIoirEJ9/vLW26X6IGhG0v+biyb7
Bqn4BOo5SXOWGj5LnlwK/hNG0Mws1vH77CqnMbeYvsHx4X5ETOnYMDaUc0iwJswe
JXK3xcn4GQPrjMfSZM/8wCua9Oa1MC1/4+Sm/FrkuAC9Mg1YAbl2FZ5bIDSDHxz7
1XRXMZfLAjxR8BqNqAeX/kwsgaihHmm1vsHRqvP/b8Xj4o1qd8u9xkitYzqkyfGT
ybPy07XKCvGZLlUH/EsjgiNZKtHpwq/vIUrpngFUIRtWWdwewBk=
=fGI6
-----END PGP SIGNATURE-----

Attachment: pgpRxzL3Xb60E.pgp
Description: PGP signature


--- End Message ---

Reply via email to