pkg/60589: pkg-vulnerabilities: ncurses CVE-2025-69720 is fixed in 6.6
| Newsgroups | gmane.os.netbsd.devel.pkgsrc.bugs |
|---|---|
| Message-ID | <[email protected]> |
>Number: 60589 >Category: pkg >Synopsis: pkg-vulnerabilities: ncurses CVE-2025-69720 is fixed in 6.6 >Confidential: no >Severity: non-critical >Priority: low >Responsible: pkg-manager >State: open >Class: change-request >Submitter-Id: net >Arrival-Date: Fri Aug 14 21:00:00 +0000 2026 >Originator: Showta Ishizaki >Release: NetBSD 11.0, pkgsrc CVS as of 2026-08-14 >Organization: >Environment: System: NetBSD 11.0 i386 Architecture: i386 Machine: i386 >Description: pkg-vulnerabilities (rev 1.776) has ncurses-[0-9]* buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-69720 written as "every version", but the release pkgsrc ships already carries the fix. CVE-2025-69720 is the stack buffer overflow in analyze_string() in progs/infocmp.c. Upstream fixed it in the ncurses 6.5 20251213 patch; NEWS records it as 20251213 + add a limit-check in infocmp -i option (report/example by Yixuan Cao). and 6.6 was cut seventeen days later: 20251230 6.6 release for upload to ftp.gnu.org so the release includes it. In the 6.6 tarball, progs/infocmp.c is rev 1.177 (2025-12-27) and analyze_string() now clamps the length: if ((len = strlen(cp)) > MAX_TERMINFO_LENGTH) len = MAX_TERMINFO_LENGTH; along with (len < sizeof(buf3)) guards on the CSI parameter paths. devel/ncurses in pkgsrc is at 6.6 (Makefile rev 1.124), so no package change is needed; only the entry is stale. >How-To-Repeat: pkg_admin fetch-pkg-vulnerabilities && pkg_admin audit on a system with ncurses 6.6 installed reports Package ncurses-6.6 has a buffer-overflow vulnerability, see https://nvd.nist.gov/vuln/detail/CVE-2025-69720 >Fix: ncurses-[0-9]* -> ncurses<6.6 Nothing to change in devel/ncurses itself; it is already at 6.6. Index: doc/pkg-vulnerabilities =================================================================== RCS file: /cvsroot/pkgsrc/doc/pkg-vulnerabilities,v retrieving revision 1.776 diff -u -r1.776 pkg-vulnerabilities --- doc/pkg-vulnerabilities 14 Aug 2026 14:49:56 -0000 1.776 +++ doc/pkg-vulnerabilities 14 Aug 2026 20:15:32 -0000 @@ -30254,7 +30254,7 @@ mongodb<7.0.31 use-after-free https://nvd.nist.gov/vuln/detail/CVE-2026-4148 mongodb<7.0.31 double-free https://nvd.nist.gov/vuln/detail/CVE-2026-4358 mumble<1.6.870 out-of-bounds-read https://nvd.nist.gov/vuln/detail/CVE-2025-71264 -ncurses-[0-9]* buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-69720 +ncurses<6.6 buffer-overflow https://nvd.nist.gov/vuln/detail/CVE-2025-69720 nghttp2<1.68.1 denial-of-service https://nvd.nist.gov/vuln/detail/CVE-2026-27135 p5-XML-Parser<2.48 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2006-10002 p5-XML-Parser<2.48 heap-overflow https://nvd.nist.gov/vuln/detail/CVE-2006-10003