Bug#1143248: trixie-pu: package open-isns/0.101-1+deb13u1
Chris Hofstaedtler <[email protected]> Sat, 01 Aug 2026 15:10:35 +0200
| Newsgroups | gmane.linux.debian.devel.release |
|---|---|
| Message-ID | <178558983512.1425221.854614914301949146.reportbug__37023.6161326588$1785590020$gmane$org@tiksta.home.arpa> |
This is a multi-part MIME message sent by reportbug. --===============2640903126150746909== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline Package: release.debian.org Severity: normal Tags: trixie X-Debbugs-Cc: [email protected], [email protected] Control: affects -1 + src:open-isns User: [email protected] Usertags: pu [ Reason ] Fix CVE-2026-55995 (bug #1143053). It is a pre-auth DoS. [ Impact ] The DoS stays unfixed. [ Tests ] There are autopkgtests. I cannot verify the bug as no reproducer is publicly available. [ Risks ] The diff seems small and nothing is obviously wrong with it. [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] Picks two upstream patches: 1) to fix the CVE 2) to fix an issue that showed up in autopkgtests, which was fixed only for forky. The issue is due to gcc changes, and IIRC autopkgtests for the version that forky inherited from trixie failed. Including it to avoid future surprises. [ Other info ] Nothing I'm aware of. Best, Chris --===============2640903126150746909== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename="open-isns_0.101-1+deb13u1.debdiff" diff -Nru open-isns-0.101/debian/changelog open-isns-0.101/debian/changelog --- open-isns-0.101/debian/changelog 2024-05-25 09:32:22.000000000 +0200 +++ open-isns-0.101/debian/changelog 2026-08-01 14:56:05.000000000 +0200 @@ -1,3 +1,17 @@ +open-isns (0.101-1+deb13u1) trixie; urgency=medium + + * Team upload. + + [ Chris Hofstaedtler ] + * d/gbp.conf: setup for trixie branch + * Pick upstream fix for CVE-2026-55995 (Closes: #1143053) + + [ Jochen Sprickerhof ] + * Pick upstream fix to "Fix the bug in compare value", to fix + autopkgtest regression. + + -- Chris Hofstaedtler <[email protected]> Sat, 01 Aug 2026 14:56:05 +0200 + open-isns (0.101-1) unstable; urgency=medium * Team upload. diff -Nru open-isns-0.101/debian/gbp.conf open-isns-0.101/debian/gbp.conf --- open-isns-0.101/debian/gbp.conf 2021-12-15 09:09:17.000000000 +0100 +++ open-isns-0.101/debian/gbp.conf 2026-08-01 14:55:01.000000000 +0200 @@ -2,7 +2,7 @@ pristine-tar = True color = auto upstream-branch = upstream/master -debian-branch = debian/master +debian-branch = debian/trixie [import-orig] dch = True diff -Nru open-isns-0.101/debian/patches/0001-Fix-issue-in-error-path-causing-double-free.patch open-isns-0.101/debian/patches/0001-Fix-issue-in-error-path-causing-double-free.patch --- open-isns-0.101/debian/patches/0001-Fix-issue-in-error-path-causing-double-free.patch 1970-01-01 01:00:00.000000000 +0100 +++ open-isns-0.101/debian/patches/0001-Fix-issue-in-error-path-causing-double-free.patch 2026-08-01 14:54:46.000000000 +0200 @@ -0,0 +1,35 @@ +From: Lee Duncan <[email protected]> +Date: Tue, 28 Jul 2026 11:07:24 -0700 +Subject: Fix issue in error path causing double-free. + +In attrs.c, when buf_get() fails and allocated memory is +freed, we also need to set the pointer to that memory to +NULL, to prevent a double free from occuring, would could +lead to a DoS attack. + +References: CVE-2026-55995 +Found-by: <[email protected]> +--- + attrs.c | 2 ++ + 1 file changed, 2 insertions(+) + +diff --git a/attrs.c b/attrs.c +index a12c222..15c930d 100644 +--- a/attrs.c ++++ b/attrs.c +@@ -1371,6 +1371,7 @@ isns_attr_type_string_decode(buf_t *bp, size_t len, isns_value_t *value) + value->iv_string = isns_malloc(len + 1); + if (!buf_get(bp, value->iv_string, len)) { + isns_free(value->iv_string); ++ value->iv_string = NULL; + return 0; + } + value->iv_string[len] = '\0'; +@@ -1546,6 +1547,7 @@ isns_attr_type_opaque_decode(buf_t *bp, size_t len, isns_value_t *value) + value->iv_opaque.ptr = isns_malloc(len); + if (!buf_get(bp, value->iv_opaque.ptr, len)) { + isns_free(value->iv_opaque.ptr); ++ value->iv_opaque.ptr = NULL; + return 0; + } + diff -Nru open-isns-0.101/debian/patches/0002-Fix-the-bug-in-compare-value.patch open-isns-0.101/debian/patches/0002-Fix-the-bug-in-compare-value.patch --- open-isns-0.101/debian/patches/0002-Fix-the-bug-in-compare-value.patch 1970-01-01 01:00:00.000000000 +0100 +++ open-isns-0.101/debian/patches/0002-Fix-the-bug-in-compare-value.patch 2026-08-01 14:55:58.000000000 +0200 @@ -0,0 +1,39 @@ +From: =?utf-8?b?5a6i5Liy5LiA5Zue?= <[email protected]> +Date: Wed, 20 Mar 2024 13:20:13 +0800 +Subject: Fix the bug in compare value + +GCC fill zero in padding bits in struct and union are undifined behavior to C std, and clang not do this. So if we use clang to compile code, we will see the error result of comparing isns_value_t. +So I fill zero in initialization of isns_value_t. +--- + include/libisns/attrs.h | 11 ++++++++--- + 1 file changed, 8 insertions(+), 3 deletions(-) + +diff --git a/include/libisns/attrs.h b/include/libisns/attrs.h +index e10f1d8..23aaace 100644 +--- a/include/libisns/attrs.h ++++ b/include/libisns/attrs.h +@@ -7,6 +7,7 @@ + #ifndef ISNS_ATTRS_H + #define ISNS_ATTRS_H + ++#include <memory.h> + #include <netinet/in.h> + #include <libisns/buffer.h> + #include <libisns/isns.h> +@@ -53,9 +54,13 @@ typedef struct isns_value { + + #define __ISNS_ATTRTYPE(type) isns_attr_type_##type + #define __ISNS_MEMBER(type) iv_##type +-#define ISNS_VALUE_INIT(type, value) \ +- (isns_value_t) { .iv_type = &__ISNS_ATTRTYPE(type), \ +- { .__ISNS_MEMBER(type) = (value) } } ++#define ISNS_VALUE_INIT(type, value) ({ \ ++ isns_value_t __v; \ ++ memset(&__v, 0, sizeof(__v)); \ ++ __v.iv_type = &__ISNS_ATTRTYPE(type); \ ++ __v.__ISNS_MEMBER(type) = (value); \ ++ __v; \ ++}) + + #define isns_attr_initialize(attrp, tag, type, value) do { \ + isns_attr_t *__attr = (attrp); \ diff -Nru open-isns-0.101/debian/patches/series open-isns-0.101/debian/patches/series --- open-isns-0.101/debian/patches/series 1970-01-01 01:00:00.000000000 +0100 +++ open-isns-0.101/debian/patches/series 2026-08-01 14:55:58.000000000 +0200 @@ -0,0 +1,2 @@ +0001-Fix-issue-in-error-path-causing-double-free.patch +0002-Fix-the-bug-in-compare-value.patch --===============2640903126150746909==--