Package: libostree-1-1 Severity: important Tags: security upstream help X-Debbugs-Cc: Debian Security Team <[email protected]> Control: fixed -1 2026.3-1
https://github.com/ostreedev/ostree/security/advisories/GHSA-7cgc-gp99-6jmm A vulnerability in libostree allows the operator of a malicious or compromised OSTree repository to serve crafted static delta content that causes clients to exhaust memory and disk space during `ostree pull`. All versions ever shipped by Debian appear to be affected. There is currently no known CVE ID. A mitigation is that if an OSTree repository is malicious or compromised, its operator can also do worse things, like inserting malicious OS images, or Flatpak apps with malicious metadata; so resource exhaustion is perhaps not a particularly exciting vulnerability. I would very much appreciate it if someone else could take responsibility for identifying the specific fixes and preparing a backport to Debian 13. Thanks, smcv _______________________________________________ Pkg-utopia-maintainers mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-utopia-maintainers
