Your message dated Mon, 16 Feb 2026 19:22:44 +0000
with message-id <[email protected]>
and subject line Bug#1096012: fixed in cmt 1.18-2
has caused the Debian Bug report #1096012,
regarding cmt Feedback Delay Line buffer-overflow
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1096012: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1096012
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: cmt
Version: 1.18-1
Severity: normal

Dear Maintainer,

The CMT ladspa plugins Feedback Delay Line have incorrect number of available 
memory to ports.

So the plugin might crash your application with SIGSEGV. See stack trace from
valgrind.

==7644== 5 errors in context 1 of 1:
==7644== Invalid write of size 8
==7644==    at 0x9DF2744: ??? (in 
/home/joelkraehemann/github/cmt_1.18/plugins/cmt.so)
==7644==    by 0x49DB9BF: g_closure_invoke (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x49F035F: ??? (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x49F17A8: ??? (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x49F7665: g_signal_emit_valist (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x49F7722: g_signal_emit (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x4F45AB2: ags_base_plugin_connect_port (ags_base_plugin.c:1804)
==7644==    by 0x109B7F: cmt_test_connect_port (cmt_test.c:335)
==7644==    by 0x4A2CA82: ??? (in /usr/lib/x86_64-linux-gnu/libcunit.so.1.0.1)
==7644==    by 0x4A2CCD7: ??? (in /usr/lib/x86_64-linux-gnu/libcunit.so.1.0.1)
==7644==    by 0x4A2D137: CU_run_all_tests (in 
/usr/lib/x86_64-linux-gnu/libcunit.so.1.0.1)
==7644==    by 0x109CF3: main (cmt_test.c:388)
==7644==  Address 0x9d7feb0 is 0 bytes after a block of size 32 alloc'd
==7644==    at 0x48455B3: operator new[](unsigned long) (in 
/usr/libexec/valgrind/vgpreload_memcheck-amd64-linux.so)
==7644==    by 0x9DF331B: ??? (in 
/home/joelkraehemann/github/cmt_1.18/plugins/cmt.so)
==7644==    by 0x62C493B: ags_cclosure_marshal_POINTER__UINT_UINT 
(ags_marshal.c:2501)
==7644==    by 0x49DB9BF: g_closure_invoke (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x49F035F: ??? (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x49F1071: ??? (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x49F7665: g_signal_emit_valist (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x49F7722: g_signal_emit (in 
/usr/lib/x86_64-linux-gnu/libgobject-2.0.so.0.8200.4)
==7644==    by 0x4F45939: ags_base_plugin_instantiate (ags_base_plugin.c:1745)
==7644==    by 0x109698: cmt_test_connect_port (cmt_test.c:180)
==7644==    by 0x4A2CA82: ??? (in /usr/lib/x86_64-linux-gnu/libcunit.so.1.0.1)
==7644==    by 0x4A2CCD7: ??? (in /usr/lib/x86_64-linux-gnu/libcunit.so.1.0.1)
==7644== 
==7644== ERROR SUMMARY: 5 errors from 1 contexts (suppressed: 0 from 0)


-- System Information:
Debian Release: trixie/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 6.12.10-amd64 (SMP w/24 CPU threads; PREEMPT)
Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE not set
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages cmt depends on:
ii  libc6       2.40-6
ii  libgcc-s1   14.2.0-14
ii  libstdc++6  14.2.0-14

cmt recommends no packages.

cmt suggests no packages.

-- no debconf information
--- src/delay.cpp.orig  2025-02-15 07:59:34.020345799 +0100
+++ src/delay.cpp       2025-02-15 07:59:58.335821276 +0100
@@ -88,7 +88,7 @@
 
   DelayLine(const unsigned long lSampleRate,
            const LADSPA_Data fMaximumDelay) 
-    : CMT_PluginInstance(4),
+    : CMT_PluginInstance(DELAY_LENGTH_COUNT),
       m_fSampleRate(LADSPA_Data(lSampleRate)),
       m_fMaximumDelay(fMaximumDelay) {
     /* Buffer size is a power of two bigger than max delay time. */

--- End Message ---
--- Begin Message ---
Source: cmt
Source-Version: 1.18-2
Done: Joël Krähemann <[email protected]>

We believe that the bug you reported is fixed in the latest version of
cmt, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Joël Krähemann <[email protected]> (supplier of updated cmt package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 16 Feb 2026 20:02:18 +0100
Source: cmt
Architecture: source
Version: 1.18-2
Distribution: unstable
Urgency: medium
Maintainer: Debian Multimedia Maintainers <[email protected]>
Changed-By: Joël Krähemann <[email protected]>
Closes: 1015371 1096012
Changes:
 cmt (1.18-2) unstable; urgency=medium
 .
   [ Olivier Humbert ]
   * debian/changelog: factorisation on the previous 1.18-1 entry.
 .
   [ Joël Krähemann ]
   * applied patch to fix bug (Closes: #1096012)
   * applied patch to fix bug (Closes: #1015371)
   * added myself to uploaders
 .
   [ Sebastian Ramacher ]
   * debian/control:
     - Bump Standards-Version
     - Drop Priority: optional
     - Drop RRR: no
Checksums-Sha1:
 ab50eea6476b897a94a9adcabab6e090c2ee2392 1357 cmt_1.18-2.dsc
 30bb2e1e83e1d3590c42e65a136c7bb4a0fa1852 5304 cmt_1.18-2.debian.tar.xz
 94d64830b6cc39ad31da664ee1086f20fadd75eb 5552 cmt_1.18-2_amd64.buildinfo
Checksums-Sha256:
 c5958ee094e7682ab7c6ad05cec4652b0a1faf3343f5361c071f0b80dd53bdb2 1357 
cmt_1.18-2.dsc
 e02ba760b4519c739d098810d2ec3e6dd313b357a59c6673131975137c8aab59 5304 
cmt_1.18-2.debian.tar.xz
 cbfbb6fbd8697dca8e12388bbed2a478b90aacb4a359a943abd6c135cefb2654 5552 
cmt_1.18-2_amd64.buildinfo
Files:
 ebf06db59f861c53e6ad626e06c4042f 1357 sound optional cmt_1.18-2.dsc
 34af24ce3c87df7561ce93f51d345721 5304 sound optional cmt_1.18-2.debian.tar.xz
 d83741979be87f50188839ca475e9cb9 5552 sound optional cmt_1.18-2_amd64.buildinfo


-----BEGIN PGP SIGNATURE-----

wr0EARYKAG8FgmmTafkJECGTazZgD82JRxQAAAAAAB4AIHNhbHRAbm90YXRpb25z
LnNlcXVvaWEtcGdwLm9yZy2jFNtyvpT7oH68e8+xbsizGZARKo76rMHjnBMicxUX
FiEEQmJ+hB2ZZ9qD4fqQIZNrNmAPzYkAAEwjAP4gKba9cg0h+HSVJItWJkQAxcvM
8j4u5L/FgR5IYzn56gD/YdJYXHpMznhDb42/n1nv8PVt/VIzCeKlnCR6Ay89GQ8=
=u3qF
-----END PGP SIGNATURE-----

Attachment: pgp72OuDRHE2t.pgp
Description: PGP signature


--- End Message ---

Reply via email to