Package: libostree-1-1 Severity: important Tags: security upstream help X-Debbugs-Cc: Debian Security Team <[email protected]> Control: fixed -1 2026.3-1
https://github.com/ostreedev/ostree/security/advisories/GHSA-xppc-j946-vcj7 A vulnerability in libostree allows the operator of a malicious or compromised OSTree repository to trigger a heap buffer overflow on 32-bit systems. All versions ever shipped by Debian appear to be affected. There is currently no known CVE ID. A mitigation is that only 32-bit architectures are affected. I would very much appreciate it if someone else could take responsibility for identifying the specific fixes and preparing a backport to Debian 13. Thanks, smcv _______________________________________________ Pkg-utopia-maintainers mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-utopia-maintainers
