Debian 10929 Published by

Debian released three security advisories to address critical flaws in popular open source software. The jq parser now includes patches for heap corruption issues that could allow attackers to execute arbitrary code or crash applications. Meanwhile the spip website engine and postorius mailing list interface received fixes for remote execution risks and a malicious script injection flaw respectively. System administrators should apply these package updates right away to keep their Debian systems secure and stable.

[DLA 4599-1] jq security update
[DSA 6296-1] spip security update
[DLA 4600-1] postorius security update




[SECURITY] [DLA 4599-1] jq security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4599-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Andreans Henriksson
May 25, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : jq
Version : 1.6-2.1+deb11u2
CVE ID : CVE-2026-32316 CVE-2026-33947 CVE-2026-33948 CVE-2026-39956
CVE-2026-39979 CVE-2026-40164 CVE-2026-41256 CVE-2026-41257
CVE-2026-43895 CVE-2026-43896 CVE-2026-44777
Debian Bug : 1136445

It was found that jq, a lightweight and flexible command-line JSON parser, was
vulnerable to multiple memory corruption attacks, which could lead to
application crashes, denial-of-service conditions, and potentially arbitrary
code execution through heap corruption when parsing untrusted input.

For Debian 11 bullseye, these problems have been fixed in version
1.6-2.1+deb11u2.

We recommend that you upgrade your jq packages.

For the detailed security status of jq please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/jq

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DSA 6296-1] spip security update


- -------------------------------------------------------------------------
Debian Security Advisory DSA-6296-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
May 25, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : spip
CVE ID : CVE-2026-8429 CVE-2026-8430 CVE-2026-48832

Multiple vulnerabilities were discovered in SPIP, a website engine for
publishing, which may result in remote code execution or an open
redirect.

For the stable distribution (trixie), these problems have been fixed in
version 4.4.15+dfsg-0+deb13u1.

We recommend that you upgrade your spip packages.

For the detailed security status of spip please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/spip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4600-1] postorius security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4600-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Daniel Leidert
May 25, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : postorius
Version : 1.3.4-2+deb11u2
CVE ID : CVE-2026-44742
Debian Bug : 1136003

A vulnerability has been discovered in postorius, a web user interface
to access GNU Mailman3.

CVE-2026-44742

If an email is sent to a mailing list with a subject containing HTML
code and placed in Held messages, the HTML code is rendered without
escaping in the title of the Held messages pop-up leading to a
Cross-site Scripting (XSS) vulnerability..

For Debian 11 bullseye, this problem has been fixed in version
1.3.4-2+deb11u2.

We recommend that you upgrade your postorius packages.

For the detailed security status of postorius please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/postorius

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS