Package: libostree-1-1
Severity: important
Tags: security upstream help
X-Debbugs-Cc: Debian Security Team <[email protected]>
Control: fixed -1 2026.3-1

https://github.com/ostreedev/ostree/security/advisories/GHSA-xppc-j946-vcj7

A vulnerability in libostree allows the operator of a malicious or 
compromised OSTree repository to trigger a heap buffer overflow on 
32-bit systems. All versions ever shipped by Debian appear to be 
affected. There is currently no known CVE ID.

A mitigation is that only 32-bit architectures are affected.

I would very much appreciate it if someone else could take 
responsibility for identifying the specific fixes and preparing a 
backport to Debian 13.

Thanks,
    smcv

_______________________________________________
Pkg-utopia-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-utopia-maintainers

Reply via email to