Debian 11028 Published by

Debian security teams released a batch of advisories to address multiple flaws across seven widely used packages. The updates patch remote code execution risks in the p7zip archiver, potential memory corruption in the libde265 video codec, a local privilege escalation in udisks2, cookie injection flaws in the async-http-client Java library, denial of service and arbitrary code execution threats in the jq JSON processor, a double-free memory bug in Redis, and dozens of kernel-level privilege escalation and information leak issues. Patched builds are now available for the trixie stable release alongside older LTS branches, with the Linux kernel jumping to 6.12.101 and Redis reaching 5.0.14 on Debian 10.

ELA-1794-1 p7zip security update (by )
[DSA 6413-1] libde265 security update
[DSA 6414-1] udisks2 security update
[DLA 4721-1] async-http-client security update
[DSA 6415-1] linux security update
[DSA 6416-1] jq security update
[DLA 4722-1] redis security update




ELA-1794-1 p7zip security update (by )


Package : p7zip

Version : 16.02+really26.02+dfsg-0+deb9u1 (stretch), 16.02+really26.02+dfsg-0+deb10u1 (buster)

Related CVEs :
CVE-2026-14266
CVE-2026-48092
CVE-2026-48095
CVE-2026-48101
CVE-2026-48102
CVE-2026-48103
CVE-2026-48104
CVE-2026-48111
CVE-2026-48112
CVE-2026-58052

Multiple vulnerabilities were discovered in p7zip, a now unmaintained
fork of 7-Zip, which itself is a file archiver handling multiple
formats.
To address these security vulnerabilities, whose fixes unfortunately
cannot be isolated, this update again replaces p7zip with a recent
7-Zip (now v26.02), slightly modified to make it reasonably compatible
with p7zip.
Among the fixed vulnerabilities, the following were made public:


CVE-2026-14266
XZ decompression heap-based buffer overflow, potentially leading
to remote code execution.


CVE-2026-48092
SquashFS Fragment Offset Overflow


CVE-2026-48095
Heap Buffer Write Overflow


CVE-2026-48101
UEFI Capsule uninitialized heap memory disclosure


CVE-2026-48102
UDF Field OOB Read


CVE-2026-48103
WIM SecurityId OOB read


CVE-2026-48104
SquashFS BlockToNode uninitialized heap read


CVE-2026-48111
UEFI DEPEX OOB Read


CVE-2026-48112
Ar SYMDEF OOB Read


CVE-2026-58052
RAR5 alternate-stream handling issue, when running on an NTFS
filesystem with transparent ADS (Alternate Data Stream) and ADS
canonicalization, letting an attacker defeat Mark-of-the-Web
warnings and spoof file content.


ELA-1794-1 p7zip security update (by )



[SECURITY] [DSA 6413-1] libde265 security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6413-1 security@debian.org
https://www.debian.org/security/ Aron Xu
August 06, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libde265
CVE ID : CVE-2024-38949 CVE-2024-38950 CVE-2025-61147 CVE-2026-45382
CVE-2026-45383 CVE-2026-49295 CVE-2026-49337 CVE-2026-49346
CVE-2026-54240 CVE-2026-54241
Debian Bug : 1074416 1129257 1140431

Multiple security issues were discovered in libde265, an open source
implementation of the H.265/HEVC video codec, which may result in denial
of service, memory exhaustion or potentially the execution of arbitrary
code if a malformed media file is processed.

For the stable distribution (trixie), these problems have been fixed in
version 1.0.15-1+deb13u1.

We recommend that you upgrade your libde265 packages.

For the detailed security status of libde265 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libde265

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6414-1] udisks2 security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6414-1 security@debian.org
https://www.debian.org/security/ Alberto Garcia
August 06, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : udisks2
CVE ID : CVE-2026-7867

The following vulnerability has been discovered in the UDisks storage
daemon:

CVE-2026-7867

Azizcan Dastan and Ozlem Ozan discovered a local privilege
escalation vulnerability in udisks2 involving the Filesystem.Mount
D-Bus method. Using the 'as-user' option, an unprivileged local
user can in some cases influence the mount execution path so that
a filesystem mount is performed in a privileged/root context
without the expected PolicyKit authorization behavior.

For the stable distribution (trixie), this problem has been fixed in
version 2.10.1-12.1+deb13u2.

We recommend that you upgrade your udisks2 packages.

For the detailed security status of udisks2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/udisks2

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4721-1] async-http-client security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4721-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
August 06, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : async-http-client
Version : 2.12.2-1+deb11u1
CVE ID : CVE-2026-55688
Debian Bug : 1141445

It was discovered that there was a potential cookie injection
vulnerability in async-http-client, Java library used to make
asynchronous HTTP requests.

CVE-2026-55688

Prevent a potential cookie injection or cookie tossing
vulnerability. ThreadSafeCookieStore stored a cookie under the
value of its Domain attribute, without verifying that the
responding host is allowed to set a cookie for that domain,
therefore leading to cookie tossing/injection issues.

For Debian 11 bullseye, this problem has been fixed in version
2.12.2-1+deb11u1.

For Debian 12 bookworm, this problem has been fixed in version
2.12.3-1+deb12u1.

We recommend that you upgrade your async-http-client packages.

For the detailed security status of async-http-client please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/async-http-client

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


[SECURITY] [DSA 6415-1] linux security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6415-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 06, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : linux
CVE ID : CVE-2025-40098 CVE-2026-45897 CVE-2026-45901 CVE-2026-53078
CVE-2026-53090 CVE-2026-64205 CVE-2026-64280 CVE-2026-64290
CVE-2026-64561 CVE-2026-64562 CVE-2026-64563 CVE-2026-64564
CVE-2026-64565 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569
CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573
CVE-2026-64574 CVE-2026-64576 CVE-2026-64577 CVE-2026-64578
CVE-2026-64579 CVE-2026-64580 CVE-2026-64583 CVE-2026-64584
Debian Bug : 1143721

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.

For the stable distribution (trixie), these problems have been fixed in
version 6.12.101-1.

We recommend that you upgrade your linux packages.

For the detailed security status of linux please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/linux

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6416-1] jq security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6416-1 security@debian.org
https://www.debian.org/security/ Aron Xu
August 07, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : jq
CVE ID : CVE-2024-53427 CVE-2026-32316 CVE-2026-40612 CVE-2026-41256
CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896
CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679
Debian Bug :

Multiple security issues were discovered in jq, a command-line JSON
processor, which could result in denial of service or potentially the
execution of arbitrary code when processing untrusted input.

This update additionally addresses three issues for which no CVE has been
assigned: GHSA-ggc9-rpv2-xgpm, GHSA-gvwx-xj9r-3frq and GHSA-gf4g-95wj-4q4r.

Two changes in behaviour follow from the fixes above. An operation whose
result would exceed the internal string length limit, such as repeating
or escaping a very large string, now terminates with the error "String
too long" instead of returning a truncated result. A comparison or
containment check on a deeply nested value now reports an error rather
than recursing until the stack is exhausted. Filters relying on the
previous behaviour will report an error where they previously appeared
to succeed.

For the stable distribution (trixie), these problems have been fixed in
version 1.7.1-6+deb13u3.

We recommend that you upgrade your jq packages.

For the detailed security status of jq please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/jq

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4722-1] redis security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4722-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
August 06, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : redis
Version : 5:5.0.14-1+deb10u11
CVE ID : CVE-2026-66373

It was discovered that there was a potential remote-code
vulnerability in Redis, the key-value database.

CVE-2026-66373

In the unusual case where an authenticated attacker could execute
the `RESTORE` command, a malicious `RESTORE` payload could have
resulted in a double-free.

For Debian 11 bullseye, this problem has been fixed in version
5:6.0.16-1+deb11u9.

For Debian 12 bookworm, this problem has been fixed in version
5:7.0.15-1~deb12u9.

We recommend that you upgrade your redis packages.

For the detailed security status of redis please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/redis

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS