------------------------------------------------------------------------- Debian LTS Advisory DLA-4707-1 [email protected] https://www.debian.org/lts/security/ Carlos Henrique Lima Melara July 30, 2026 https://wiki.debian.org/LTS -------------------------------------------------------------------------
Package : gsasl Version : 1.10.0-4+deb11u3 2.2.0-1+deb12u2 CVE ID : CVE-2026-56968 It was discovered that missing input sanitising in the NTLM client of the GNU SASL library could result in memory disclosure. For Debian 11 bullseye, this problem has been fixed in version 1.10.0-4+deb11u3. For Debian 12 bookworm, this problem has been fixed in version 2.2.0-1+deb12u2. We recommend that you upgrade your gsasl packages. For the detailed security status of gsasl please refer to its security tracker page at: https://security-tracker.debian.org/tracker/gsasl Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
signature.asc
Description: PGP signature
