Debian 11012 Published by

Debian released security advisories covering critical updates for Samba, OpenJDK Java runtimes, HPLIP printing software, libxfont1, and libraw image library across stable and LTS distributions. The advisories remediate vulnerabilities that could allow attackers to achieve privilege escalation, arbitrary code execution, domain takeover, sandbox bypasses, or data corruption through specially crafted inputs targeting buffer handling and decoder routines in these applications.

[DSA 6401-1] samba security update
[DLA 4703-1] openjdk-17 security update
[DLA 4702-1] openjdk-11 security update
ELA-1787-1 openjdk-11 security update (by )
[DSA 6402-1] hplip security update
ELA-1788-1 libxfont1 security update (by )
[DLA 4704-1] libraw security update




[SECURITY] [DSA 6401-1] samba security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6401-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 28, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : samba
CVE ID : CVE-2026-6949 CVE-2026-58216 CVE-2026-58218 CVE-2026-58221
CVE-2026-58222 CVE-2026-58224

Several vulnerabilities have been discovered in Samba, a SMB/CIFS file,
print, and login server for Unix, which might result in denial of
service, domain takeover, information disclosure or privilege
escalation.

For the stable distribution (trixie), these problems have been fixed in
version 2:4.22.10+dfsg-0+deb13u2.

We recommend that you upgrade your samba packages.

For the detailed security status of samba please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/samba

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4703-1] openjdk-17 security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4703-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
July 28, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : openjdk-17
Version : 17.0.20+8-1~deb11u1 17.0.20+8-1~deb12u1
CVE ID : CVE-2026-41254 CVE-2026-46917 CVE-2026-46968 CVE-2026-47010
CVE-2026-47021 CVE-2026-47027 CVE-2026-47059 CVE-2026-47063
CVE-2026-60147

Several vulnerabilities have been discovered in the OpenJDK Java
runtime, which may result in denial of service, information disclosure
or bypass of sandbox restrictions.

For Debian 11 bullseye, these problems have been fixed in version
17.0.20+8-1~deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
17.0.20+8-1~deb12u1.

We recommend that you upgrade your openjdk-17 packages.

For the detailed security status of openjdk-17 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/openjdk-17

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DLA 4702-1] openjdk-11 security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4702-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
July 28, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : openjdk-11
Version : 11.0.32+9-2~deb11u1
CVE ID : CVE-2026-41254 CVE-2026-46917 CVE-2026-46968 CVE-2026-47010
CVE-2026-47021 CVE-2026-47027 CVE-2026-47057 CVE-2026-47058
CVE-2026-47059 CVE-2026-47063 CVE-2026-60147

Several vulnerabilities have been discovered in the OpenJDK Java
runtime, which may result in denial of service, information disclosure
or bypass of sandbox restrictions.

For Debian 11 bullseye, these problems have been fixed in version
11.0.32+9-2~deb11u1.

We recommend that you upgrade your openjdk-11 packages.

For the detailed security status of openjdk-11 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/openjdk-11

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

ELA-1787-1 openjdk-11 security update (by )


Package : openjdk-11

Version : 11.0.32+9-2~deb10u1 (buster)

Related CVEs :
CVE-2026-41254
CVE-2026-46917
CVE-2026-46968
CVE-2026-47010
CVE-2026-47021
CVE-2026-47027
CVE-2026-47057
CVE-2026-47058
CVE-2026-47059
CVE-2026-47063
CVE-2026-60147

Several vulnerabilities have been discovered in the OpenJDK Java
runtime, which may result in denial of service, information disclosure
or bypass of sandbox restrictions.


ELA-1787-1 openjdk-11 security update (by )



[SECURITY] [DSA 6402-1] hplip security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6402-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 28, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : hplip
CVE ID : CVE-2026-8631 CVE-2026-8632
Debian Bug : 1137374

Two vulnerabilities were discovered in hplip, the HP Linux Printing and
Imaging System, which may result in privilege escalation or arbitrary
code execution.

For the stable distribution (trixie), these problems have been fixed in
version 3.22.10+dfsg0-8.1+deb13u1.

We recommend that you upgrade your hplip packages.

For the detailed security status of hplip please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/hplip

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


ELA-1788-1 libxfont1 security update (by )


Package : libxfont1

Version : 1:1.5.2-4+deb9u1 (stretch)

Related CVEs :
CVE-2026-56001
CVE-2026-56002
CVE-2026-56003

CVE-2026-56001
A heap buffer overflow in BitmapScaleBitmaps in due to an overflowing
32-bit size.

CVE-2026-56002
A heap bufferflow in pcfReadFont() due to missing glyph bounds
checking.

CVE-2026-56003
A heap buffer overflow due to missing size checking in the property
buffer when parsing PCF files in ComputeScaledProperties().


ELA-1788-1 libxfont1 security update (by )



[SECURITY] [DLA 4704-1] libraw security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4704-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Guilhem Moulin
July 29, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : libraw
Version : 0.20.2-1+deb11u3 0.20.2-2.1+deb12u2
CVE ID : CVE-2026-5342 CVE-2026-20884 CVE-2026-20889 CVE-2026-21413
CVE-2026-24660
Debian Bug : 1132655 1133845

Multiple vulnerabilities were found in libraw, a raw image decoder
library, which could lead to application crash, information disclosure
or data corruption.

CVE-2026-5342

Biniam F. Demissie discovered an out-of-bounds read in the decoder
routine for RAW image files from Nikon digital cameras.

CVE-2026-20884

Francesco Benvenuto discovered an integer overflow vulnerability
in the decoder routine for deflate-compressed floating-point DNG
RAW files, which may lead to heap buffer overflow via specially
crafted input file.

CVE-2026-20889

Francesco Benvenuto discovered a heap-based buffer overflow
vulnerability in the thumbnail extraction routine for RAW image
files from Sigma/Foveon X3F digital cameras.

CVE-2026-21413

Francesco Benvenuto discovered a heap-based buffer overflow
vulnerability in the lossless JPEG decoder used for processing
compressed RAW data from various camera formats.

CVE-2026-24660

Francesco Benvenuto discovered a heap-based buffer overflow
vulnerability in the Huffman decompression routine for RAW image
files from Sigma/Foveon X3F digital cameras.

For Debian 11 bullseye, these problems have been fixed in version
0.20.2-1+deb11u3.

For Debian 12 bookworm, these problems have been fixed in version
0.20.2-2.1+deb12u2.

We recommend that you upgrade your libraw packages.

For the detailed security status of libraw please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libraw

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS