Debian 11014 Published by

Debian issued two security advisories, addressing critical flaws in the calibre e-book manager and the nss cryptography library. The calibre update (DLA-4705-1) resolves five vulnerabilities across CVE-2026-27810, CVE-2026-27824, CVE-2026-30853, CVE-2026-33205, and CVE-2026-33206, which include path traversal risks in the RocketBook plugin, HTTP response header injection, brute-force protection bypasses via spoofed headers, and server-side request forgery that could expose data from the ebook sandbox. The nss advisory (DSA-6403-1) fixes CVE-2026-16389 in the Mozilla Network Security Service library, where processing a maliciously crafted certificate could trigger arbitrary code execution. Users running Debian 11 bullseye should upgrade calibre to version 5.12.0+dfsg-1+deb11u5 immediately, while trixie users must apply nss update 2:3.110-1+deb13u4 to close these security gaps.

[DLA 4705-1] calibre security update
[DSA 6403-1] nss security update




[SECURITY] [DLA 4705-1] calibre security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4705-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Abhijith PA
July 29, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : calibre
Version : 5.12.0+dfsg-1+deb11u5
CVE ID : CVE-2026-27810 CVE-2026-27824 CVE-2026-30853 CVE-2026-33205
CVE-2026-33206

Multiple vulnerabilities have been discovered in calibre, an e-book
manager.

CVE-2026-27810

An HTTP Response Header Injection vulnerability in the calibre
Content Server allows any authenticated user to inject arbitrary
HTTP headers into server responses via an unsanitized
`content_disposition` query parameter in the `/get/` and
`/data-files/get/` endpoints

CVE-2026-27824

The calibre Content Server's brute-force protection mechanism uses
a ban key derived from both `remote_addr` and the
`X-Forwarded-For` header. Since the `X-Forwarded-For` header is
read directly from the HTTP request without any validation or
trusted-proxy configuration, an attacker can bypass IP-based bans
by simply changing or adding this header, rendering the
brute-force protection completely ineffective. This is
particularly dangerous for calibre servers exposed to the
internet, where brute-force protection is the primary defense
against credential stuffing and password guessing attacks.

CVE-2026-30853

A path traversal vulnerability in the RocketBook (.rb) input
plugin (src/calibre/ebooks/rb/reader.py) allows an attacker to
write arbitrary files to any path writable by the calibre process
when a user opens or converts a crafted .rb file.

CVE-2026-33205

A Server-Side Request Forgery vulnerability in the
background-image endpoint of calibre e-book reader's web view
allows an attacker to perform blind GET requests to arbitrary URLs
and exfiltrate information out from the ebook sandbox.

CVE-2026-33206

A path traversal vulnerability exists in Calibre' handling of
images in Markdown and other similar text-based files allowing an
attacker to include arbitrary files from the file system into the
converted book. Additionally, missing authentication and
server-side request forgery in the background-image endpoint in the
ebook reader web view allow the files to be exfiltrated without
additional interaction.

For Debian 11 bullseye, these problems have been fixed in version
5.12.0+dfsg-1+deb11u5.

We recommend that you upgrade your calibre packages.

For the detailed security status of calibre please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/calibre

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DSA 6403-1] nss security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6403-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 29, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : nss
CVE ID : CVE-2026-16389

Tomoya Nakanishi discovered a flaw in nss, the Mozilla Network Security
Service library, which may result in execution of arbitrary code if a
specially crafted certificate is processed.

For the stable distribution (trixie), this problem has been fixed in
version 2:3.110-1+deb13u4.

We recommend that you upgrade your nss packages.

For the detailed security status of nss please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/nss

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/